High severity8.8NVD Advisory· Published Jun 27, 2019· Updated Jun 17, 2026
CVE-2018-6156
CVE-2018-6156
Description
Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.
Affected products
10cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- osv-coords3 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
< 92.0-1.2+ 2 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 93.0.4577.82-1.1
- (no CPE)range: < 128.5.1-1.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.