V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
The product reads data past the end, or before the beginning, of the intended buffer.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://crbug.com/659475 | issue tracking exploit |
http://www.securityfocus.com/bid/94079 | broken link third party advisory vdb entry |
http://www.securitytracker.com/id/1037224 | broken link third party advisory vdb entry |
http://rhn.redhat.com/errata/RHSA-2016-2672.html | third party advisory vendor advisory |
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html | release notes vendor advisory |