The WebKit::WebPluginContainerImpl::handleEvent function in Google Chrome before Blink M11 allows an attacker to cause a denial of service (crash) via the htmlpluginelement.cpp plugin.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://bugs.chromium.org/p/chromium/issues/detail?id=76474 | vendor advisory mailing list exploit |
http://trac.webkit.org/changeset/81795 | patch vendor advisory mailing list |
http://trac.webkit.org/changeset/81891 | patch vendor advisory mailing list |