vendor:
Chromium
by:
Project Zero
8,8
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Chromium
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2018
Stack Overflow in Js::InterpreterStackFrame::INTERPRETERLOOPNAME()
This vulnerability is a stack overflow in Js::InterpreterStackFrame::INTERPRETERLOOPNAME() which is a snippet of the method that interprets a javascript function's bytecode. If it fails to allocate Js::Constants::MinStackInterpreter bytes to the stack, it throws an exception which leads to the following code. The stackScopeSlots contains the local variables that were supposed to be initialized at (b). So it results in accessing the uninitialized pointers.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all local variables are properly initialized before they are used.