Google Chrome 'dtoa()' Remote Code Execution Vulnerability
BID:36565
Info
Google Chrome 'dtoa()' Remote Code Execution Vulnerability
| Bugtraq ID: | 36565 |
| Class: | Unknown |
| CVE: |
CVE-2009-0689 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2009 12:00AM |
| Updated: | Mar 19 2015 09:45AM |
| Credit: | Maksymilian Arciemowicz |
| Vulnerable: |
Red Hat Enterprise Linux Long Life 5.6 server Red Hat Enterprise Linux Long Life 5.3 Server Google Chrome 3.0.195 .21 Google Chrome 2.0.172 .43 Google Chrome 2.0.172 .37 Google Chrome 2.0.172 .33 Google Chrome 2.0.172 .31 Google Chrome 2.0.172 .30 Google Chrome 1.0.154 .61 Google Chrome 0.3.154 9 Google Chrome 0.2.149 .30 Google Chrome 0.2.149 .29 Google Chrome 0.2.149 .27 Google Chrome 1.0.154.65 Google Chrome 1.0.154.64 Google Chrome 1.0.154.59 Google Chrome 1.0.154.55 Google Chrome 1.0.154.53 Google Chrome 1.0.154.48 Google Chrome 1.0.154.46 Google Chrome 1.0.154.36 Avaya IP Office Application Server 8.1 Avaya IP Office Application Server 8.0 Avaya Aura Session Manager 5.2 Avaya Aura Messaging 6.1 Avaya Aura Messaging 6.0.1 Avaya Aura Messaging 6.0 Avaya Aura Communication Manager Utility Services 6.2 Avaya Aura Communication Manager Utility Services 6.1 Avaya Aura Communication Manager Utility Services 6.0 Avaya Aura Communication Manager 6.0.1 Avaya Aura Communication Manager 6.0 Avaya Aura Communication Manager 5.2 Avaya Aura Communication Manager 5.1 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2.3 Avaya Aura Application Enablement Services 5.2.2 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: |
Google Chrome 3.0.195 .24 |
Discussion
Google Chrome 'dtoa()' Remote Code Execution Vulnerability
Google Chrome is prone to a remote code-execution vulnerability.
Successful exploits will allow an attacker to execute arbitrary code in the Chrome sandbox. Failed attacks may cause denial-of-service conditions.
NOTE: This issue is related to BID 35510 (Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability), but because of differences in the code base, it is being assigned its own record.
This issue affects versions prior to Chrome 3.0.195.24.
Google Chrome is prone to a remote code-execution vulnerability.
Successful exploits will allow an attacker to execute arbitrary code in the Chrome sandbox. Failed attacks may cause denial-of-service conditions.
NOTE: This issue is related to BID 35510 (Multiple BSD Distributions 'gdtoa/misc.c' Memory Corruption Vulnerability), but because of differences in the code base, it is being assigned its own record.
This issue affects versions prior to Chrome 3.0.195.24.
Exploit / POC
Google Chrome 'dtoa()' Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Google Chrome 'dtoa()' Remote Code Execution Vulnerability
Solution:
The vendor has released a fix. Please see the references for details.
Solution:
The vendor has released a fix. Please see the references for details.
References
Google Chrome 'dtoa()' Remote Code Execution Vulnerability
References:
References:
- Google Chrome Homepage (Google)
- Stable Channel Update (Google)
- php security update (RHSA-2014-0311) (Avaya)