PT-2009-2463 · Google · Google Chrome

Le Duc Anh

·

Publicado

2009-08-18

·

Atualizado

2018-10-11

·

CVE-2008-6994

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome version 0.2.149.27
Description The issue is a stack-based buffer overflow in the SaveAs feature, specifically in the SaveFileAsWithFilter function in win util.cc. This allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element. The overflow is triggered when the user saves the page and a long filename is generated. It might also be possible to exploit this issue via an HTTP response that includes a long filename in a Content-Disposition header.
Recommendations For Google Chrome version 0.2.149.27, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, avoid saving web pages with long TITLE elements or long filenames. Restrict access to the SaveAs feature until a patch is available.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6994

Produtos afetados

Google Chrome