browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade chromium-browser | Dec 12, 2016 | Nov 14, 2016 |
| Freebsd | — | Upgrade chromiumUpgrade chromium-npapiUpgrade chromium-pulse | Nov 14, 2016 | Nov 10, 2016 |
| Gentoo Linux | — | Upgrade www-client/chromium. | Oct 30, 2017 | Nov 22, 2016 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Oct 31, 2019 | Nov 10, 2016 |
| Redhat_linux | — | Upgrade chromium-browser-debuginfoUpgrade chromium-browser | Nov 14, 2016 | Nov 14, 2016 |
| Suse | — | Upgrade chromium | Nov 15, 2016 | Nov 14, 2016 |
| Ubuntu | — | Upgrade liboxideqtcore0 | Dec 2, 2016 | Nov 14, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub