Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
BID:35722
Info
Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
| Bugtraq ID: | 35722 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2555 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2009 12:00AM |
| Updated: | Apr 13 2015 09:09PM |
| Credit: | Google Chrome security team |
| Vulnerable: |
Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 1.0.154 .61 Google Chrome 0.3.154 9 Google Chrome 0.2.149 .30 Google Chrome 0.2.149 .29 Google Chrome 0.2.149 .27 Google Chrome 1.0.154.65 Google Chrome 1.0.154.64 Google Chrome 1.0.154.59 Google Chrome 1.0.154.55 Google Chrome 1.0.154.53 Google Chrome 1.0.154.48 Google Chrome 1.0.154.46 Google Chrome 1.0.154.36 |
| Not Vulnerable: |
Google Chrome 2.0.172 .37 |
Discussion
Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
Google Chrome is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will allow the attacker to execute arbitrary code in the Chrome sandbox. Failed attacks may cause denial-of-service conditions caused by a renderer (tab) crash.
This issue affects versions prior to Chrome 2.0.172.37.
Google Chrome is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will allow the attacker to execute arbitrary code in the Chrome sandbox. Failed attacks may cause denial-of-service conditions caused by a renderer (tab) crash.
This issue affects versions prior to Chrome 2.0.172.37.
Exploit / POC
Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
Solution:
The vendor has released a fix. Please see the references for details.
Solution:
The vendor has released a fix. Please see the references for details.
References
Google Chrome JavaScript Regular Expression Handling Remote Code Execution Vulnerability
References:
References:
- Google Chrome Homepage (Google)
- Stable, Beta update: Bug fixes (Google)