common/partialcircularbuffer.cc in Google Chrome before 43.0.2357.65 does not properly handle wraps, which allows remote attackers to bypass a sandbox protection mechanism or cause a denial of service (out-of-bounds write) via vectors that trigger a write operation with a large amount of data, related to the PartialCircularBuffer::Write and PartialCircularBuffer::DoWrite functions.
{
"binaries": [
{
"binary_version": "43.0.2357.81-0ubuntu0.14.04.1.1089",
"binary_name": "chromium-browser"
},
{
"binary_version": "43.0.2357.81-0ubuntu0.14.04.1.1089",
"binary_name": "chromium-browser-l10n"
},
{
"binary_version": "43.0.2357.81-0ubuntu0.14.04.1.1089",
"binary_name": "chromium-chromedriver"
},
{
"binary_version": "43.0.2357.81-0ubuntu0.14.04.1.1089",
"binary_name": "chromium-codecs-ffmpeg"
},
{
"binary_version": "43.0.2357.81-0ubuntu0.14.04.1.1089",
"binary_name": "chromium-codecs-ffmpeg-extra"
}
],
"availability": "No subscription required"
}