Risk | High |
Patch available | YES |
Number of vulnerabilities | 9 |
CVE-ID | CVE-2018-5150 CVE-2018-5154 CVE-2018-5155 CVE-2018-5157 CVE-2018-5158 CVE-2018-5159 CVE-2018-5168 CVE-2018-5178 CVE-2018-5183 |
CWE-ID | CWE-119 CWE-416 CWE-20 CWE-79 CWE-264 CWE-120 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Red Hat Enterprise Linux Server Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems Operating systems & Components / Operating system Red Hat Enterprise Linux for Power Operating systems & Components / Operating system Red Hat Enterprise Linux Desktop Operating systems & Components / Operating system Red Hat Enterprise Linux Workstation Operating systems & Components / Operating system |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 9 vulnerabilities.
EUVDB-ID: #VU12566
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5150
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to boundary error when handling malicious input. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability result may result in system compromise.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12528
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5154
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to use-after-free error while enumerating attributes during SVG animations with clip paths. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability result may result in system compromise.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12529
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5155
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to use-after-free error while adjusting layout during SVG animations with text paths. A remote attacker can trick the victim into visiting a specially crafted website, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability result may result in system compromise.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12534
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-5157
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass same-origin policy on the target system.
The weakness exists due to improper input validation. A remote attacker can trick the victim into visiting a specially crafted website, bypass same-origin protections for the PDF viewer and cause a malicious site to intercept messages meant for the viewer and retrieve PDF files restricted to viewing by an authenticated user on a third-party website.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12535
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-5158
CWE-ID:
CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Exploit availability: No
DescriptionThe disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to the PDF viewer does not sufficiently sanitize PostScript calculator functions. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks
MitigationInstall update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12530
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5159
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to integer overflow in the Skia library while 32-bit integer use in an array without integer overflow checks. A remote attacker can trick the victim into visiting a specially crafted website, trigger out-of-bounds write and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability result may result in system compromise.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12551
Risk: Low
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-5168
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to improper privileges or access controls. A remote attacker can manipulate the baseURI
property of the theme element, bypass security restrictions and cause lightweight themes to be installed without user interaction which could contain offensive or embarrassing images.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12578
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5178
CWE-ID:
CWE-120 - Buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU12577
Risk: High
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2018-5183
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
Install update from vendor's website.
Vulnerable software versionsRed Hat Enterprise Linux Server: 7 - 7.5
Red Hat Enterprise Linux for IBM z Systems: 7 - 7.5
Red Hat Enterprise Linux for Power: 7 - 9
Red Hat Enterprise Linux Desktop: 7
Red Hat Enterprise Linux Workstation: 7
CPE2.3https://access.redhat.com/errata/RHSA-2018:1415
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.