vendor:
Chrome
by:
Chase Higgins
7,5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Chrome
Affected Version From: Google Chrome 5.0.375.9 dev
Affected Version To: Google Chrome 5.0.375.9 dev
Patch Exists: NO
Related CWE: N/A
CPE: a:google:chrome
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac OSX 10.5.8
2010
Multiple Browsers Audio Tag DoS Vulnerability
This vulnerability allows an attacker to cause a denial of service (DoS) by sending a specially crafted ogg file to a vulnerable web server. The server will then crash due to the large number of audio tags in the HTML code. The crash reporter for Mac OSX 10.5.8 seems to think this is a EXEC_BAD_ACCESS.
Mitigation:
The best way to mitigate this vulnerability is to ensure that the web server is not vulnerable to this attack by limiting the number of audio tags that can be included in a single HTML page.