The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-browser-dbg",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-chromedriver-dbg",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-codecs-ffmpeg-dbg",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra-dbg",
"binary_version": "31.0.1650.63-0ubuntu1~20131204.1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "libv8-3.14-dbg",
"binary_version": "3.14.5.8-5ubuntu1"
},
{
"binary_name": "libv8-3.14-dev",
"binary_version": "3.14.5.8-5ubuntu1"
},
{
"binary_name": "libv8-3.14.5",
"binary_version": "3.14.5.8-5ubuntu1"
},
{
"binary_name": "libv8-dev",
"binary_version": "3.14.5.8-5ubuntu1"
}
]
}