Описание
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
An integer-overflow flaw was found in V8's Zone class when allocating new memory (Zone::New() and Zone::NewExpand()). An attacker with the ability to manipulate a large zone could crash the application or, potentially, execute arbitrary code with the application privileges.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | v8 | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | v8 | Will not fix | ||
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | v8 | Will not fix | ||
Red Hat OpenShift Enterprise 2 | nodejs010-nodejs | Will not fix | ||
Red Hat OpenShift Enterprise 2 | v8 | Will not fix | ||
Red Hat OpenShift Enterprise 3 | nodejs | Not affected | ||
Red Hat OpenShift Enterprise 3 | v8 | Not affected | ||
Red Hat OpenStack Platform 11 (Ocata) | v8 | Not affected | ||
Red Hat Software Collections | nodejs010-nodejs | Will not fix | ||
Red Hat Software Collections | v8314-v8 | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.6 Medium
CVSS3
5.1 Medium
CVSS2
Связанные уязвимости
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as us ...
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
EPSS
5.6 Medium
CVSS3
5.1 Medium
CVSS2