CVE-2018-6109
09.01.2019, 19:29
readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page.Enginsight
Vendor | Product | Version |
---|---|---|
chrome | 𝑥 < 66.0.3359.117 | |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
redhat | enterprise_linux_desktop | 6.0 |
redhat | enterprise_linux_server | 6.0 |
redhat | enterprise_linux_workstation | 6.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||
oxide-qt |
|
Common Weakness Enumeration
References