Vulnerabilities > CVE-2008-6995 - Numeric Errors vulnerability in Google Chrome 0.2.149.27
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Google Chrome Browser 0.2.149.27 malicious link DoS Vulnerability. CVE-2008-6995. Dos exploit for windows platform |
file | exploits/windows/dos/6353.txt |
id | EDB-ID:6353 |
last seen | 2016-02-01 |
modified | 2008-09-03 |
platform | windows |
port | |
published | 2008-09-03 |
reporter | Rishi Narang |
source | https://www.exploit-db.com/download/6353/ |
title | Google Chrome Browser 0.2.149.27 - DoS Vulnerability |
type | dos |
Nessus
NASL family | Windows |
NASL id | GOOGLE_CHROME_0_2_149_29.NASL |
description | The version of Google Chrome installed on the remote host is earlier than 0.2.149.29. Such versions are reportedly affected by several issues : - A buffer overflow involving long filenames that display in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 34197 |
published | 2008-09-12 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/34197 |
title | Google Chrome < 0.2.149.29 Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2008-09/0028.html
- http://code.google.com/p/chromium/issues/detail?id=122
- http://evilfingers.com/advisory/google_chrome_poc.php
- http://osvdb.org/47908
- http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/net/base/escape.cc?r1=1757&r2=1760&pathrev=1760
- http://www.securityfocus.com/bid/30983
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44899
- https://www.evilfingers.com/advisory/Google_Chrome_Browser_0.2.149.27_in_chrome_dll.php
- https://www.exploit-db.com/exploits/6353