Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the renderer process via a crafted (1) image or (2) canvas.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://code.google.com/p/chromium/issues/detail?id=10736 | exploit |
http://www.vupen.com/english/advisories/2009/1266 | vdb entry |
http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html | patch vendor advisory |
http://secunia.com/advisories/35014 | third party advisory |
http://osvdb.org/54248 | vdb entry |
http://www.securitytracker.com/id?1022175 | vdb entry |
http://www.securityfocus.com/bid/34859 | vdb entry |
http://code.google.com/p/skia/source/detail?r=159 |