Headline
CVE-2016-1669: Issue 1945313002: Version 5.0.71.47 (cherry-pick)
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
Created:
4 years, 7 months ago by Jakob Kummerow
Modified:
4 years, 7 months ago
Reviewers:
Camillo Bruni
CC:
Paweł Hajdan Jr., ulan, v8-reviews_googlegroups.com
Base URL:
https://chromium.googlesource.com/v8/[email protected]
Target Ref:
refs/pending/branch-heads/5.0
Project:
v8
Visibility:
Public.
More Reviews
Description
Version 5.0.71.47 (cherry-pick) Merged 3a9bfecfe41737aaf0dbf92ce68352f8acaaaf73 Fix overflow issue in Zone::New BUG=chromium:606115 LOG=N [email protected] Committed: https://chromium.googlesource.com/v8/v8/+/557b84becbfe9f6d10c281bb0b2dbb75403a497f
Patch Set 1 #
Created: 4 years, 7 months ago
Download [raw] [tar.bz2]
Unified diffs
Side-by-side diffs
Delta from patch set
Stats (+9 lines, -3 lines)
Patch
M
include/v8-version.h
View
1 chunk
+1 line, -1 line
0 comments
Download
M
src/zone.cc
View
2 chunks
+8 lines, -2 lines
0 comments
Download
Messages
Total messages: 4 (1 generated)
Expand Messages | Collapse Messages | Show Generated Messages | Hide Generated Messages
Jakob Kummerow
4 years, 7 months ago (2016-05-04 14:15:08 UTC) #1
Camillo Bruni
lgtm
4 years, 7 months ago (2016-05-04 14:16:33 UTC) #2
Jakob Kummerow
4 years, 7 months ago (2016-05-04 14:20:06 UTC) #4
Message was sent while issue was closed.
Committed patchset #1 (id:1) manually as 557b84becbfe9f6d10c281bb0b2dbb75403a497f.
Expand Messages | Collapse Messages | Show Generated Messages | Hide Generated Messages
Issue 1945313002: Version 5.0.71.47 (cherry-pick) (Closed)
Created 4 years, 7 months ago by Jakob Kummerow
Modified 4 years, 7 months ago
Reviewers: Camillo Bruni
Base URL: https://chromium.googlesource.com/v8/[email protected]
Comments: 0