CVE-2008-6994: Buffer Overflow
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in winutil.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated. NOTE: it might be possible to exploit this issue via an HTTP response that includes a long filename in a Content-Disposition header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6994?
CVE-2008-6994 has been classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2008-6994?
To fix CVE-2008-6994, upgrade Google Chrome to a version later than 0.2.149.27.
What causes CVE-2008-6994?
CVE-2008-6994 is caused by a stack-based buffer overflow in the SaveAs feature of Google Chrome.
What versions of Google Chrome are affected by CVE-2008-6994?
CVE-2008-6994 affects Google Chrome version 0.2.149.27.
Can CVE-2008-6994 be exploited remotely?
Yes, CVE-2008-6994 can be exploited by user-assisted remote attackers through specially crafted web pages.