Google Chrome before 23.0.1271.91 does not properly perform a cast of an unspecified variable during handling of the INPUT element, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted HTML document.
References
Link | Resource |
---|---|
http://googlechromereleases.blogspot.com/2012/11/stable-channel-update.html | Vendor Advisory |
https://code.google.com/p/chromium/issues/detail?id=159829 | Patch Issue Tracking |
http://lists.opensuse.org/opensuse-security-announce/2012-12/msg00004.html | Third Party Advisory |
http://osvdb.org/87885 | Broken Link |
http://www.securitytracker.com/id?1027815 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/56684 | Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/80296 | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15929 |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2012-11-27 17:55
Updated : 2018-10-30 09:27
NVD link : CVE-2012-5136
Mitre link : CVE-2012-5136
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
- chrome
opensuse
- opensuse