PT-2009-3943 · Google · Google Chrome+2
Published
2009-05-07
·
Updated
2009-05-19
·
CVE-2009-1442
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions 1.x before 1.0.154.64
Google Chrome versions 2.x
Description
The issue is related to multiple integer overflows in Skia, which is used in Google Chrome and possibly Android. This might allow remote attackers to execute arbitrary code in the renderer process via a crafted image or canvas.
Recommendations
For Google Chrome versions 1.x before 1.0.154.64, update to version 1.0.154.64 or later.
For Google Chrome versions 2.x, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Google Chrome
Skia