First published: Sat May 14 2016(Updated: )
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =13.1 | |
Red Hat Enterprise Linux Desktop | =6.0 | |
Red Hat Enterprise Linux Server Supplementary | =6.0 | |
Red Hat Enterprise Linux Server Supplementary EUS | =6.7z | |
Red Hat Enterprise Linux Workstation Supplementary | =6.0 | |
Google Chrome (Trace Event) | <=50.0.2661.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1665 has been assigned a medium severity level due to its potential to expose sensitive information.
To fix CVE-2016-1665, update Google Chrome to version 50.0.2661.94 or later.
CVE-2016-1665 affects Google Chrome versions up to 50.0.2661.87.
CVE-2016-1665 allows remote attackers to obtain sensitive information through crafted JavaScript code.
CVE-2016-1665 impacts multiple operating systems including certain versions of openSUSE and Red Hat Enterprise Linux.