Vulnerabilities > CVE-2009-1442 - Numeric Errors vulnerability in Google Chrome

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
google
CWE-189
nessus

Summary

Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the renderer process via a crafted (1) image or (2) canvas.

Common Weakness Enumeration (CWE)

Nessus

NASL familyWindows
NASL idGOOGLE_CHROME_1_0_154_64.NASL
descriptionThe version of Google Chrome installed on the remote host is earlier than 1.0.154.64. Such versions are reportedly affected by multiple vulnerabilities : - A failure to properly validate input from a renderer (tab) process could allow an attacker to crash the browser and possibly run arbitrary code with the privileges of the logged on user. (CVE-2009-1441) - A failure to check the result of integer multiplication when computing image sizes could allow a specially crafted image or canvas to cause a tab to crash and possibly allow an attacker to execute arbitrary code inside the (sandboxed) renderer process. (CVE-2009-1442)
last seen2020-06-01
modified2020-06-02
plugin id38699
published2009-05-07
reporterThis script is Copyright (C) 2009-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/38699
titleGoogle Chrome < 1.0.154.64 Multiple Overflows