redhat · CVE-2016-1663

Quick triage

Priority: high 公开: 2016-04-28 00:00:00 UTC Updated: 2016-04-28 00:00:00 UTC

查看: Official redhat advisory, NVD, CVE.org · CVE 详情

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.

Description:

The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.

cvelogic Threat Intelligence