V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 54.0.2840.90 (excluding) | |
Red Hat Enterprise Linux 6 Supplementary | RedHat | chromium-browser-0:54.0.2840.90-1.el6 | * |
Chromium-browser | Ubuntu | artful | * |
Chromium-browser | Ubuntu | bionic | * |
Chromium-browser | Ubuntu | cosmic | * |
Chromium-browser | Ubuntu | devel | * |
Chromium-browser | Ubuntu | precise | * |
Chromium-browser | Ubuntu | trusty | * |
Chromium-browser | Ubuntu | upstream | * |
Chromium-browser | Ubuntu | xenial | * |
Chromium-browser | Ubuntu | yakkety | * |
Chromium-browser | Ubuntu | zesty | * |
Libv8 | Ubuntu | precise | * |
Libv8-3.14 | Ubuntu | artful | * |
Libv8-3.14 | Ubuntu | bionic | * |
Libv8-3.14 | Ubuntu | cosmic | * |
Libv8-3.14 | Ubuntu | devel | * |
Libv8-3.14 | Ubuntu | esm-apps/bionic | * |
Libv8-3.14 | Ubuntu | esm-apps/xenial | * |
Libv8-3.14 | Ubuntu | trusty | * |
Libv8-3.14 | Ubuntu | upstream | * |
Libv8-3.14 | Ubuntu | xenial | * |
Libv8-3.14 | Ubuntu | yakkety | * |
Libv8-3.14 | Ubuntu | zesty | * |
Oxide-qt | Ubuntu | artful | * |
Oxide-qt | Ubuntu | trusty | * |
Oxide-qt | Ubuntu | upstream | * |
Oxide-qt | Ubuntu | vivid/stable-phone-overlay | * |
Oxide-qt | Ubuntu | xenial | * |
Oxide-qt | Ubuntu | yakkety | * |
Oxide-qt | Ubuntu | zesty | * |