CVE-2016-1632
published 2016-03-06CVE-2016-1632: The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended…
PriorityP341high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.35%
68.7th percentile
The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | <= 48.0.2564.116 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffm3-7v29-m7x8: The Extensions subsystem in Google Chrome before 49
ghsa_unreviewed·2022-05-17
CVE-2016-1632 [HIGH] GHSA-ffm3-7v29-m7x8: The Extensions subsystem in Google Chrome before 49
The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
OSV
CVE-2016-1632: The Extensions subsystem in Google Chrome before 49
osv·2016-03-06·CVSS 8.8
CVE-2016-1632 [HIGH] CVE-2016-1632: The Extensions subsystem in Google Chrome before 49
The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
Red Hat
chromium-browser: bad cast in Extensions
vendor_redhat·2016-03-02·CVSS 8.8
CVE-2016-1632 [HIGH] chromium-browser: bad cast in Extensions
chromium-browser: bad cast in Extensions
The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
bugzilla·2016-04-12·CVSS 6.5
CVE-2016-3658 [MEDIUM] CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
CVE-2016-3658 libtiff: out-of-bounds read in the TIFFWriteDirectoryTagLongLong8Array function
A vulnerability was found in the libtiff library. Using a tiffset command on a maliciously crafted image could result in a denial-of-service.
Vulnerable code:
/libtiff/tif_dirwrite.c: 1625
1623 for (q=p, ma=value, mb=0; mb0xFFFFFFFF)
1626 {
1627 TIFFErrorExt(tif->tif_clientdata,module,
1628 "Attempt to write value larger than 0xFFFFFFFF in Classic TIFF file.");
1629 _TIFFfree(p);
1630 return(0);
1631 }
1632 *q= (uint32)(*ma);
1633 }
References:
http://www.openwall.com/lists/oss-security/2016/04/08/12
Discussion:
External References:
http://bugzilla.maptools.org/show_bug.cgi?id=2546
---
*** This bug has been marked as a duplicate of bug 1185805 ***
---
Statement:
This flaw was found to
Bugzilla
CVE-2016-1632 chromium-browser: bad cast in Extensions
bugzilla·2016-03-03·CVSS 8.8
CVE-2016-1632 [HIGH] CVE-2016-1632 chromium-browser: bad cast in Extensions
CVE-2016-1632 chromium-browser: bad cast in Extensions
A bad cast flaw was found in the Extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=549986
External References:
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2016:0359 https://rhn.redhat.com/errata/RHSA-2016-0359.html
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://www.debian.org/security/2016/dsa-3507http://www.securityfocus.com/bid/84008http://www.securitytracker.com/id/1035185https://code.google.com/p/chromium/issues/detail?id=549986https://codereview.chromium.org/1433293004https://security.gentoo.org/glsa/201603-09http://googlechromereleases.blogspot.com/2016/03/stable-channel-update.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00028.htmlhttp://www.debian.org/security/2016/dsa-3507http://www.securityfocus.com/bid/84008http://www.securitytracker.com/id/1035185https://code.google.com/p/chromium/issues/detail?id=549986https://codereview.chromium.org/1433293004https://security.gentoo.org/glsa/201603-09
2016-03-06
Published