CVE-2016-1624
published 2016-02-14CVE-2016-1624: Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.35%
68.4th percentile
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | brotli | < brotli 0.3.0+dfsg-3 (bookworm) | brotli 0.3.0+dfsg-3 (bookworm) |
| debian | debian_linux | — | — |
| chrome | <= 48.0.2564.103 | — | |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5mx7-hhwx-7mq8: Integer underflow in the ProcessCommandsInternal function in dec/decode
ghsa_unreviewed·2022-05-14
CVE-2016-1624 [HIGH] CWE-119 GHSA-5mx7-hhwx-7mq8: Integer underflow in the ProcessCommandsInternal function in dec/decode
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.
OSV
oxide-qt vulnerabilities
osv·2016-02-18·CVSS 8.8
CVE-2016-1623 [HIGH] oxide-qt vulnerabilities
oxide-qt vulnerabilities
The DOM implementation in Chromium did not properly restrict frame-attach
operations from occurring during or after frame-detach operations. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1623)
An integer underflow was discovered in Brotli. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2016-1624)
OSV
CVE-2016-1624: Integer underflow in the ProcessCommandsInternal function in dec/decode
osv·2016-02-14·CVSS 8.8
CVE-2016-1624 [HIGH] CVE-2016-1624: Integer underflow in the ProcessCommandsInternal function in dec/decode
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.
Ubuntu
Oxide vulnerabilities
vendor_ubuntu·2016-02-18·CVSS 8.8
CVE-2016-1623 [HIGH] Oxide vulnerabilities
Title: Oxide vulnerabilities
Summary: Several security issues were fixed in Oxide.
The DOM implementation in Chromium did not properly restrict frame-attach
operations from occurring during or after frame-detach operations. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same-origin restrictions.
(CVE-2016-1623)
An integer underflow was discovered in Brotli. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking the
program. (CVE-2016-1624)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
chromium-browser: buffer overflow in Brotli
vendor_redhat·2016-02-09·CVSS 8.8
CVE-2016-1624 [HIGH] chromium-browser: buffer overflow in Brotli
chromium-browser: buffer overflow in Brotli
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.
Debian
CVE-2016-1624: brotli - Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Bro...
vendor_debian·2016·CVSS 8.8
CVE-2016-1624 [HIGH] CVE-2016-1624: brotli - Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Bro...
Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.
Scope: local
bookworm: resolved (fixed in 0.3.0+dfsg-3)
bullseye: resolved (fixed in 0.3.0+dfsg-3)
forky: resolved (fixed in 0.3.0+dfsg-3)
sid: resolved (fixed in 0.3.0+dfsg-3)
trixie: resolved (fixed in 0.3.0+dfsg-3)
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183http://www.ubuntu.com/usn/USN-2895-1https://code.google.com/p/chromium/issues/detail?id=583607https://codereview.chromium.org/1662313002https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/02/stable-channel-update_9.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00104.htmlhttp://lists.opensuse.org/opensuse-updates/2016-02/msg00119.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0241.htmlhttp://www.debian.org/security/2016/dsa-3486http://www.securityfocus.com/bid/83125http://www.securitytracker.com/id/1035183http://www.ubuntu.com/usn/USN-2895-1https://code.google.com/p/chromium/issues/detail?id=583607https://codereview.chromium.org/1662313002https://security.gentoo.org/glsa/201603-09
2016-02-14
Published