Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michal Bednarski

#50792of 53,635
4.3Total CVSS
Vulnerabilities · 1
PT-2015-7357
4.3
2015-12-06
Google · Google Chrome · CVE-2015-6783
**Name of the Vulnerable Software and Affected Versions** crazy linker (aka Crazy Linker) versions prior to the version included in Google Chrome 47.0.2526.73 Google Chrome versions prior to 47.0.2526.73 **Description** The issue is related to the `FindStartOffsetOfFileInZipFile` function in `crazy linker zip.cpp`, which improperly searches for an EOCD record. This allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. **Recommendations** For crazy linker (aka Crazy Linker) versions prior to the version included in Google Chrome 47.0.2526.73, update to a version included in Google Chrome 47.0.2526.73 or later. For Google Chrome versions prior to 47.0.2526.73, update to version 47.0.2526.73 or later.