PT-2016-4890 · Opera+5 · Opera+6

Atte Kettunen

·

Published

2016-04-28

·

Updated

2024-06-15

·

CVE-2016-1660

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Blink versions prior to 50.0.2661.94 Google Chrome versions prior to 50.0.2661.94 Opera versions prior to 50.0.2661.94 is not specified, however, it is mentioned that Opera is affected.
Description The issue is related to the mishandling of assertions in the WTF::BitArray and WTF::double conversion::Vector classes. This can be exploited by remote attackers via a crafted web site, potentially leading to a denial of service (out-of-bounds write) or other unspecified impacts.
Recommendations For Google Chrome versions prior to 50.0.2661.94, update to version 50.0.2661.94 or later. For Blink versions prior to 50.0.2661.94, update to version 50.0.2661.94 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability in Opera.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2194
CVE-2016-1660
DSA-3564-1
MGASA-2016-0160
OPENSUSE-SU-2016_1208-1
OPENSUSE-SU-2016_1209-1
OPENSUSE-SU-2016_1655-1
OPENSUSE-SU-2024:10171-1
OPENSUSE-SU-2024:12948-1
RHSA-2016:0707
RHSA-2016_0707
USN-2960-1

Affected Products

Alt Linux
Blink
Google Chrome
Opera
Red Hat
Suse
Ubuntu