First published: Tue Aug 18 2009(Updated: )
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | =0.2.149.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6996 has been classified as a medium severity vulnerability.
To fix CVE-2008-6996, upgrade Google Chrome to a later version where this vulnerability is resolved.
CVE-2008-6996 can be exploited to cause denial of service through disk consumption or to execute other vulnerabilities via executable file downloads.
CVE-2008-6996 affects Google Chrome version 0.2.149.27.
CVE-2008-6996 does not present a direct phishing risk but facilitates malicious downloads which could lead to phishing attacks.