Уязвимость use-after-free в реализации каскадных таблиц стилей (CSS) в Google Chrome через некорректную обработку псевдоэлемента :first-letter
Описание
В Google Chrome обнаружена уязвимость типа use-after-free в реализации каскадных таблиц стилей (CSS). Она связана с некорректной обработкой псевдоэлемента :first-letter. Это позволяет злоумышленникам вызвать DoS атаку, а также может приводить к другим неизвестным последствиям.
Затронутые версии ПО
Уязвимость присутствует в версиях Google Chrome до 17.0.963.83.
Тип уязвимости
Удалённое выполнение кода или DoS атака
Ссылки
- ExploitVendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Broken Link
- Not Applicable
- Not Applicable
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- ExploitVendor Advisory
- Release NotesVendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
Use-after-free vulnerability in the Cascading Style Sheets (CSS) imple ...
Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 17.0.963.83 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the :first-letter pseudo-element.
EPSS
6.8 Medium
CVSS2