First published: Sun Apr 19 2015(Updated: )
The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Ubuntu | =15.04 | |
Google V8 | <=4.2.77.7 | |
Google Chrome | <=42.0.2311.60 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1242 has been classified as a high severity vulnerability due to its potential for denial of service and possible remote exploitation.
CVE-2015-1242 affects users of Google Chrome versions before 42.0.2311.90 and Google V8 versions up to 4.2.77.7, along with certain versions of Ubuntu Linux and Debian GNU/Linux.
To fix CVE-2015-1242, update Google Chrome to version 42.0.2311.90 or later and ensure your V8 engine is updated to version 4.2.77.8 or newer.
CVE-2015-1242 can be exploited by attackers to cause denial of service through specially crafted JavaScript code.
CVE-2015-1242 was disclosed in April 2015 as part of a security update for Google Chrome.