CVE-2008-7061
Google Chrome 0.2.149 - Malformed 'title' Tag Remote Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994. NOTE: there is inconsistent information about the environments under which this issue exists.
El gestor de "tooltips" (chrome/views/tooltip_manager.cc) de Google Chrome v0.2.149.29 Build 1798 y, posiblemente, de otras versiones anteriores a la v0.2.149.30 permite a atacantes remotos provocar una denegación de servicio (consumo de toda la CPU o caída de la aplicación) a través de una etiqueta con un atributo de título largo, que no es adecuadamente manejada cuando se muestra un "tooltip". Es una vulnerabilidad diferente a la CVE-2008-6994. NOTA: existen incosistencias en la información sobre los entornos bajo los que esta vulnerabilidad existe.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-09-02 First Exploit
- 2009-08-24 CVE Reserved
- 2009-08-24 CVE Published
- 2024-01-11 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-399: Resource Management Errors
CAPEC
References (17)
URL | Tag | Source |
---|---|---|
http://googlechromereleases.blogspot.com/2008/09/beta-release-0214930.html | X_refsource_confirm | |
http://src.chromium.org/viewvc/chrome?view=rev&revision=2042 | X_refsource_confirm | |
http://www.blackhat.org.il/exploits/chrome-freeze-exploit.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/496078/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/496094/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/496101/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/496126/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/496146/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/496172/100/100/threaded | Mailing List | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45039 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | 0.2.149.29 Search vendor "Google" for product "Chrome" and version "0.2.149.29" | - |
Affected
|