PT-2016-1346 · Google+5 · Google Chrome+5

Cloudfuzzer

·

Publicado

2016-03-02

·

Atualizado

2024-06-15

·

CVE-2016-1634

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 49.0.2623.75 Opera (affected versions not specified)
Description The issue is related to a use-after-free vulnerability in the StyleResolver::appendCSSStyleSheet function. This vulnerability can be exploited by a remote attacker using a specially crafted web site, potentially causing a denial of service or other unspecified impact. The vulnerability is triggered by Cascading Style Sheets (CSS) style invalidation during a certain subtree-removal action.
Recommendations For Google Chrome versions prior to 49.0.2623.75, update to version 49.0.2623.75 or later to resolve the issue. For Opera, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1283
BDU:2016-00645
CVE-2016-1634
DSA-3507-1
MGASA-2016-0127
OPENSUSE-SU-2016_0664-1
OPENSUSE-SU-2016_0684-1
OPENSUSE-SU-2016_0729-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:0359
RHSA-2016_0359
USN-2920-1

Produtos afetados

Alt Linux
Google Chrome
Opera
Red Hat
Suse
Ubuntu