Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6070

Опубликовано: 14 нояб. 2018
Источник: debian
EPSS Низкий

Описание

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browserfixed65.0.3325.146-1package
chromium-browserend-of-lifejessiepackage
chromium-browserend-of-lifewheezypackage

EPSS

Процентиль: 59%
0.00373
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 6.5
redhat
почти 8 лет назад

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 6.1
nvd
около 7 лет назад

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

CVSS3: 6.1
github
больше 3 лет назад

Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

suse-cvrf
почти 8 лет назад

Security update for Chromium

EPSS

Процентиль: 59%
0.00373
Низкий