A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
References
Link | Resource |
---|---|
https://crbug.com/664411 | Exploit Issue Tracking Patch Vendor Advisory |
https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html | Release Notes Vendor Advisory |
https://www.exploit-db.com/exploits/42175/ | Third Party Advisory VDB Entry |
https://security.gentoo.org/glsa/201612-11 | Third Party Advisory |
http://www.securityfocus.com/bid/94633 | VDB Entry Third Party Advisory |
http://rhn.redhat.com/errata/RHSA-2016-2919.html | Third Party Advisory |
Information
Published : 2019-01-09 11:29
Updated : 2019-01-16 05:43
NVD link : CVE-2016-9651
Mitre link : CVE-2016-9651
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_server
- enterprise_linux_workstation
- chrome