CVE-2018-18358

medium

Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

References

http://www.securityfocus.com/bid/106084

https://access.redhat.com/errata/RHSA-2018:3803

https://chromereleases.googleblog.com/2018/12/stable-channel-update-for-desktop.html

https://crbug.com/899126

https://security.gentoo.org/glsa/201908-18

https://www.debian.org/security/2018/dsa-4352

Details

Source: MITRE

Published: 2018-12-11

Updated: 2019-08-17

Type: CWE-20

Risk Information

CVSS v2

Base Score: 2.9

Vector: AV:A/AC:M/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 5.5

Severity: LOW

CVSS v3

Base Score: 5.7

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 2.1

Severity: MEDIUM