The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Debian_linux | Debian | 8.0 (including) | 8.0 (including) |
Debian_linux | Debian | 9.0 (including) | 9.0 (including) |
Red Hat Enterprise Linux 6 Supplementary | RedHat | chromium-browser-0:49.0.2623.108-1.el6 | * |
Chromium-browser | Ubuntu | artful | * |
Chromium-browser | Ubuntu | bionic | * |
Chromium-browser | Ubuntu | cosmic | * |
Chromium-browser | Ubuntu | devel | * |
Chromium-browser | Ubuntu | precise | * |
Chromium-browser | Ubuntu | trusty | * |
Chromium-browser | Ubuntu | upstream | * |
Chromium-browser | Ubuntu | wily | * |
Chromium-browser | Ubuntu | xenial | * |
Chromium-browser | Ubuntu | yakkety | * |
Chromium-browser | Ubuntu | zesty | * |
Libv8 | Ubuntu | precise | * |
Libv8-3.14 | Ubuntu | artful | * |
Libv8-3.14 | Ubuntu | bionic | * |
Libv8-3.14 | Ubuntu | cosmic | * |
Libv8-3.14 | Ubuntu | devel | * |
Libv8-3.14 | Ubuntu | esm-apps/bionic | * |
Libv8-3.14 | Ubuntu | esm-apps/xenial | * |
Libv8-3.14 | Ubuntu | trusty | * |
Libv8-3.14 | Ubuntu | upstream | * |
Libv8-3.14 | Ubuntu | wily | * |
Libv8-3.14 | Ubuntu | xenial | * |
Libv8-3.14 | Ubuntu | yakkety | * |
Libv8-3.14 | Ubuntu | zesty | * |
Oxide-qt | Ubuntu | artful | * |
Oxide-qt | Ubuntu | trusty | * |
Oxide-qt | Ubuntu | upstream | * |
Oxide-qt | Ubuntu | vivid/stable-phone-overlay | * |
Oxide-qt | Ubuntu | wily | * |
Oxide-qt | Ubuntu | xenial | * |
Oxide-qt | Ubuntu | yakkety | * |
Oxide-qt | Ubuntu | zesty | * |