vendor:
Chrome
by:
Tobias Klein
7,5
CVSS
HIGH
Out-of-Bounds Array Indexing Bug
119
CWE
Product Name: Chrome
Affected Version From: Google Chrome <= 4.1.249.1042 (Build 42199)
Affected Version To: Google Chrome <= 4.1.249.1042 (Build 42199)
Patch Exists: Yes
Related CWE: N/A
CPE: a:google:chrome
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2010
Google Chrome OOB Array Indexing Bug
Google Chrome is vulnerable to an out-of-bounds array indexing bug, caused by the improper handling of FTP PWD command server responses. By persuading a victim to visit a specially-crafted web site containing an iframe pointing to a malicious FTP server, a remote attacker could exploit this bug and cause the browser to crash.
Mitigation:
Google has released an updated version of Chrome which addresses this vulnerability.