hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 40.0.2214.85 (including) | |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | chromium-browser-0:40.0.2214.91-1.el6_6 | * |
Chromium-browser | Ubuntu | artful | * |
Chromium-browser | Ubuntu | bionic | * |
Chromium-browser | Ubuntu | cosmic | * |
Chromium-browser | Ubuntu | devel | * |
Chromium-browser | Ubuntu | lucid | * |
Chromium-browser | Ubuntu | precise | * |
Chromium-browser | Ubuntu | trusty | * |
Chromium-browser | Ubuntu | upstream | * |
Chromium-browser | Ubuntu | utopic | * |
Chromium-browser | Ubuntu | vivid | * |
Chromium-browser | Ubuntu | wily | * |
Chromium-browser | Ubuntu | xenial | * |
Chromium-browser | Ubuntu | yakkety | * |
Chromium-browser | Ubuntu | zesty | * |
Libv8-3.14 | Ubuntu | artful | * |
Libv8-3.14 | Ubuntu | bionic | * |
Libv8-3.14 | Ubuntu | cosmic | * |
Libv8-3.14 | Ubuntu | devel | * |
Libv8-3.14 | Ubuntu | esm-apps/bionic | * |
Libv8-3.14 | Ubuntu | esm-apps/xenial | * |
Libv8-3.14 | Ubuntu | trusty | * |
Libv8-3.14 | Ubuntu | utopic | * |
Libv8-3.14 | Ubuntu | vivid | * |
Libv8-3.14 | Ubuntu | wily | * |
Libv8-3.14 | Ubuntu | xenial | * |
Libv8-3.14 | Ubuntu | yakkety | * |
Libv8-3.14 | Ubuntu | zesty | * |
Oxide-qt | Ubuntu | artful | * |
Oxide-qt | Ubuntu | trusty | * |
Oxide-qt | Ubuntu | upstream | * |
Oxide-qt | Ubuntu | utopic | * |
Oxide-qt | Ubuntu | vivid | * |
Oxide-qt | Ubuntu | vivid/stable-phone-overlay | * |
Oxide-qt | Ubuntu | wily | * |
Oxide-qt | Ubuntu | xenial | * |
Oxide-qt | Ubuntu | yakkety | * |
Oxide-qt | Ubuntu | zesty | * |