PT-2015-1100 · Google+4 · Google Chrome+5
Jakob
·
Published
2015-04-14
·
Updated
2025-09-29
·
CVE-2015-1242
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google V8 versions prior to 4.2.77.8
Google Chrome versions prior to 42.0.2311.90
Description
The issue allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization. This is due to a problem in the ReduceTransitionElementsKind function in hydrogen-check-elimination.cc.
Recommendations
For Google V8 versions prior to 4.2.77.8, update to version 4.2.77.8 or later.
For Google Chrome versions prior to 42.0.2311.90, update to version 42.0.2311.90 or later.
As a temporary workaround, consider restricting the execution of crafted JavaScript code to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Opera
Red Hat
Ubuntu
V8