PT-2016-2077 · Google+5 · V8+6

Published

2016-05-11

·

Updated

2025-09-29

·

CVE-2016-1669

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google V8 versions prior to 5.0.71.47 Google Chrome versions prior to 50.0.2661.102
Description The issue is caused by a buffer overflow in the Zone::New function in zone.cc, which can be exploited by remote attackers using specially crafted JavaScript code. This can lead to a denial of service or possibly other unspecified impacts.
Recommendations For Google V8 versions prior to 5.0.71.47, update to version 5.0.71.47 or later to resolve the issue. For Google Chrome versions prior to 50.0.2661.102, update to version 50.0.2661.102 or later to resolve the issue. As a temporary workaround, consider restricting the execution of crafted JavaScript code until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2016-1755
ALT-PU-2016-2194
BDU:2016-01428
CVE-2016-1669
DSA-3590-1
MGASA-2016-0183
MGASA-2016-0307
OPENSUSE-SU-2016_1304-1
OPENSUSE-SU-2016_1655-1
OPENSUSE-SU-2016_2496-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:10247-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:1080
RHSA-2016_1080
RHSA-2017:0002
RHSA-2017:0879
RHSA-2017:0880
RHSA-2017:0881
RHSA-2017:0882
RHSA-2018:0336
USN-2960-1

Affected Products

Alt Linux
Google Chrome
Opera
Red Hat
Suse
Ubuntu
V8