Уязвимость use-after-free в Google Chrome при обработке flexbox в сочетании с плавающими элементами
Описание
В Google Chrome до версии 17.0.963.65 существует уязвимость use-after-free, связанная с использованием flexbox (также известного как flexible box) в сочетании с плавающими элементами. Эта уязвимость позволяет злоумышленникам вызвать DoS атаку или, возможно, иметь неопределённые последствия.
Затронутые версии ПО
- Google Chrome < 17.0.963.65
Тип уязвимости
- Use-after-free
Ссылки
- Vendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Not Applicable
- Not Applicable
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allow ...
Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a flexbox (aka flexible box) in conjunction with the floating of elements.
EPSS
6.8 Medium
CVSS2