Short Name |
HTTP:STC:CHROME:BUG-REPORT-CE1 |
---|---|
Severity |
Medium |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Google Chrome Uninitialized bug_report_pointer Code Execution1 |
Release Date |
2015/09/30 |
Update Number |
2541 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known code execution vulnerability in Google Chrome. It is due to accessing an uninitialized memory during processing of URLs with rouge extensions; specifically to an invalid write in the browser process when trying to delete an invalid bug_report_ pointer. An attacker can leverage this by enticing a target user to open a crafted Web file. A successful attack can allow an attacker to execute arbitrary code in the security context of the logged in user. An unsuccessful attack can cause an abnormal termination of the affected product.