CVE-2015-1217: High severity google chrome (trace event) vulnerability
The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1217?
The severity of CVE-2015-1217 is categorized as moderate due to its potential to cause denial of service.
How do I fix CVE-2015-1217?
To fix CVE-2015-1217, users should update Google Chrome to version 41.0.2272.76 or later.
What systems are affected by CVE-2015-1217?
CVE-2015-1217 affects Google Chrome versions before 41.0.2272.76 and specific Red Hat and Ubuntu Linux versions.
What type of attack is possible with CVE-2015-1217?
CVE-2015-1217 allows remote attackers to cause a denial of service.
Who discovered CVE-2015-1217?
CVE-2015-1217 was discovered in the V8JavaScript engine used in Google Chrome.