First published: Thu Apr 28 2016(Updated: )
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted web site.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =13.1 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.7z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 | |
Google Chrome (Trace Event) | <=50.0.2661.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-1660 has been classified as a high-severity vulnerability due to its potential for causing denial of service.
To fix CVE-2016-1660, update Google Chrome to the latest version that exceeds 50.0.2661.94.
CVE-2016-1660 affects multiple versions of Google Chrome and several Red Hat Enterprise Linux distributions.
CVE-2016-1660 facilitates remote attackers in executing denial of service attacks through crafted web content.
CVE-2016-1660 involves mishandling assertions in the WTF::BitArray and WTF::double_conversion::Vector classes within the Blink rendering engine.