Уязвимость DoS атаки через ошибку на один байт в OpenType Sanitizer в Google Chrome
Описание
В OpenType Sanitizer в Google Chrome до версии 18.0.1025.142 существует уязвимость, связанная с ошибкой на один байт. Эта уязвимость позволяет злоумышленникам вызвать DoS атаку или, возможно, иметь другие неопределенные последствия, используя специально подготовленный файл формата OpenType.
Затронутые версии ПО
- Google Chrome версии до 18.0.1025.142
Тип уязвимости
- DoS атака
Ссылки
- Vendor Advisory
- Release NotesVendor Advisory
- Broken Link
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Not Applicable
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Vendor Advisory
- Release NotesVendor Advisory
- Broken Link
- Not Applicable
Уязвимые конфигурации
Одно из
EPSS
6.8 Medium
CVSS2
Дефекты
Связанные уязвимости
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18. ...
Off-by-one error in the OpenType Sanitizer in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted OpenType file.
EPSS
6.8 Medium
CVSS2