Описание
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | 34.0.1847.116-0ubuntu2 | 
| esm-infra-legacy/trusty | DNE  | trusty/esm was DNE [trusty was not-affected [34.0.1847.116-0ubuntu2]] | 
| lucid | ignored  | end of life | 
| precise | released  | 34.0.1847.116-0ubuntu~1.12.04.0~pkg884 | 
| quantal | released  | 34.0.1847.116-0ubuntu~1.12.10.0~pkg900 | 
| saucy | released  | 34.0.1847.116-0ubuntu~1.13.10.0~pkg991 | 
| trusty | not-affected  | 34.0.1847.116-0ubuntu2 | 
| trusty/esm | DNE  | trusty was not-affected [34.0.1847.116-0ubuntu2] | 
| upstream | released  | 34.0.1847.116 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | |
| esm-infra-legacy/trusty | DNE  | trusty/esm was DNE [trusty was not-affected] | 
| lucid | DNE  | |
| precise | DNE  | |
| quantal | DNE  | |
| saucy | DNE  | |
| trusty | not-affected  | |
| trusty/esm | DNE  | trusty was not-affected | 
| upstream | not-affected  | 
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call.
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as ...
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, which allows remote attackers to cause a denial of service (out-of-bounds read) via a window.atob method call.
Уязвимость браузера Google Chrome, позволяющая злоумышленнику вызвать отказ в обслуживании
EPSS
5 Medium
CVSS2