CVE-2016-5198

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.
References
Link Resource
http://rhn.redhat.com/errata/RHSA-2016-2672.html Third Party Advisory
http://www.securityfocus.com/bid/94079 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037224 Broken Link Third Party Advisory VDB Entry
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html Release Notes Vendor Advisory
https://crbug.com/659475 Exploit Issue Tracking
http://rhn.redhat.com/errata/RHSA-2016-2672.html Third Party Advisory
http://www.securityfocus.com/bid/94079 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037224 Broken Link Third Party Advisory VDB Entry
https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html Release Notes Vendor Advisory
https://crbug.com/659475 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:53

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2016-2672.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2016-2672.html - Third Party Advisory
References () http://www.securityfocus.com/bid/94079 - Broken Link, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94079 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037224 - Broken Link, Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1037224 - Broken Link, Third Party Advisory, VDB Entry
References () https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html - Release Notes, Vendor Advisory () https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html - Release Notes, Vendor Advisory
References () https://crbug.com/659475 - Exploit, Issue Tracking () https://crbug.com/659475 - Exploit, Issue Tracking

28 Jun 2024, 14:19

Type Values Removed Values Added
First Time Linux
Microsoft
Apple macos
Linux linux Kernel
Apple
Google android
Redhat enterprise Linux Desktop
Redhat enterprise Linux Server
Redhat
Microsoft windows
Redhat enterprise Linux Workstation
References () http://rhn.redhat.com/errata/RHSA-2016-2672.html - () http://rhn.redhat.com/errata/RHSA-2016-2672.html - Third Party Advisory
References () http://www.securityfocus.com/bid/94079 - () http://www.securityfocus.com/bid/94079 - Broken Link, Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037224 - () http://www.securitytracker.com/id/1037224 - Broken Link, Third Party Advisory, VDB Entry
References () https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html - () https://chromereleases.googleblog.com/2016/11/stable-channel-update-for-desktop.html - Release Notes, Vendor Advisory
References () https://crbug.com/659475 - () https://crbug.com/659475 - Exploit, Issue Tracking
CPE cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Information

Published : 2017-01-19 05:59

Updated : 2025-02-20 18:06


NVD link : CVE-2016-5198

Mitre link : CVE-2016-5198

CVE.ORG link : CVE-2016-5198


JSON object : View

Products Affected

google

  • chrome
  • android

redhat

  • enterprise_linux_desktop
  • enterprise_linux_server
  • enterprise_linux_workstation

microsoft

  • windows

linux

  • linux_kernel

apple

  • macos
CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write