Short Name |
HTTP:STC:CHROME:V8-ARRAY-OOB
|
Severity |
High
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Google Chrome V8 Dehoistable Array Out Of Bound Read
|
Release Date |
2013/12/22
|
Update Number |
2329
|
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: Google Chrome V8 Dehoistable Array Out Of Bound Read
This signature detects attempts to exploit a known vulnerability in the Google Chrome. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the user.
Extended Description
The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index.
Affected Products
- google chrome 31.0.1650.0
- google chrome 31.0.1650.10
- google chrome 31.0.1650.11
- google chrome 31.0.1650.12
- google chrome 31.0.1650.13
- google chrome 31.0.1650.14
- google chrome 31.0.1650.15
- google chrome 31.0.1650.16
- google chrome 31.0.1650.17
- google chrome 31.0.1650.18
- google chrome 31.0.1650.19
- google chrome 31.0.1650.2
- google chrome 31.0.1650.20
- google chrome 31.0.1650.22
- google chrome 31.0.1650.23
- google chrome 31.0.1650.25
- google chrome 31.0.1650.26
- google chrome 31.0.1650.27
- google chrome 31.0.1650.28
- google chrome 31.0.1650.29
- google chrome 31.0.1650.3
- google chrome 31.0.1650.30
- google chrome 31.0.1650.31
- google chrome 31.0.1650.32
- google chrome 31.0.1650.33
- google chrome 31.0.1650.34
- google chrome 31.0.1650.35
- google chrome 31.0.1650.36
- google chrome 31.0.1650.37
- google chrome 31.0.1650.38
- google chrome 31.0.1650.39
- google chrome 31.0.1650.4
- google chrome 31.0.1650.41
- google chrome 31.0.1650.42
- google chrome 31.0.1650.43
- google chrome 31.0.1650.44
- google chrome 31.0.1650.45
- google chrome 31.0.1650.46
- google chrome 31.0.1650.47
- google chrome 31.0.1650.48
- google chrome 31.0.1650.49
- google chrome 31.0.1650.5
- google chrome 31.0.1650.50
- google chrome 31.0.1650.51
- google chrome 31.0.1650.52
- google chrome 31.0.1650.53
- google chrome 31.0.1650.54
- google chrome 31.0.1650.55
- google chrome 31.0.1650.57
- google chrome 31.0.1650.58
- google chrome 31.0.1650.59
- google chrome 31.0.1650.6
- google chrome 31.0.1650.60
- google chrome 31.0.1650.61
- google chrome 31.0.1650.7
- google chrome 31.0.1650.8
- google chrome 31.0.1650.9
- google chrome up to 31.0.1650.62
- google v8 3.22.0
- google v8 3.22.1
- google v8 3.22.10
- google v8 3.22.11
- google v8 3.22.12
- google v8 3.22.13
- google v8 3.22.14
- google v8 3.22.15
- google v8 3.22.16
- google v8 3.22.17
- google v8 3.22.18
- google v8 3.22.19
- google v8 3.22.2
- google v8 3.22.20
- google v8 3.22.21
- google v8 3.22.22
- google v8 3.22.23
- google v8 3.22.3
- google v8 3.22.4
- google v8 3.22.5
- google v8 3.22.6
- google v8 3.22.7
- google v8 3.22.8
- google v8 3.22.9
- google v8 up to 3.22.24
References