First published: Thu May 26 2016(Updated: )
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Chrome | <51.0.2704.63 | 51.0.2704.63 |
Google Chrome | <=50.0.2661.102 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =15.10 | |
Canonical Ubuntu Linux | =16.04 | |
Debian Debian Linux | =8.0 | |
openSUSE Leap | =42.1 | |
openSUSE openSUSE | =13.2 | |
Redhat Enterprise Linux Desktop | =6.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Workstation | =6.0 | |
SUSE Linux Enterprise | =12.0 | |
Google V8 | <=5.1.281 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.