CVE-2018-18358

Publication date 11 December 2018

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.7 · Medium

Score breakdown

Description

Lack of special casing of localhost in WPAD files in Google Chrome prior to 71.0.3578.80 allowed an attacker on the local network segment to proxy resources on localhost via a crafted WPAD file.

Status

Package Ubuntu Release Status
chromium-browser 18.10 cosmic
Fixed 71.0.3578.80-0ubuntu0.18.10.1
18.04 LTS bionic
Fixed 71.0.3578.80-0ubuntu0.18.04.1
16.04 LTS xenial
Fixed 71.0.3578.80-0ubuntu0.16.04.1
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 5.7 · Medium

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N


Access our resources on patching vulnerabilities