Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-A3473F5A-A739-11E6-AFAA-E8E0B747A45A (CVE-2016-5202): chromium -- multiple vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-A3473F5A-A739-11E6-AFAA-E8E0B747A45A (CVE-2016-5202): chromium -- multiple vulnerabilities

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
11/09/2016
Created
07/25/2018
Added
11/14/2016
Modified
10/31/2019

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From VID-A3473F5A-A739-11E6-AFAA-E8E0B747A45A:

Google Chrome Releases reports:

4 security fixes in this release, including:

[643948] High CVE-2016-5199: Heap corruption in FFmpeg. Credit to

Paul Mehta

[658114] High CVE-2016-5200: Out of bounds memory access in V8. Credit to

Choongwoo Han

[660678] Medium CVE-2016-5201: Info leak in extensions. Credit to

Rob Wu

[662843] CVE-2016-5202: Various fixes from internal audits,

fuzzing and other initiatives

Solution(s)

  • freebsd-upgrade-package-chromium
  • freebsd-upgrade-package-chromium-npapi
  • freebsd-upgrade-package-chromium-pulse

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;