首页 网络安全 安全学院 查看内容

Google Chrome Browser 0.2.149.27 malicious link DoS Vulnerability

2009-2-4 17:35 698 0

摘要: Software:Google Chrome Browser 0.2.149.27 Tested:Windows XP Professional SP3 Result:Google Chrome C...
关键词: Chrome Google with evilfingers undefined Crashes 149.27 Result com user

Software:Google Chrome Browser 0.2.149.27 Tested:Windows XP Professional SP3 Result:Google Chrome Crashes with All Tabs Problem:An issue exists in how chrome behaves with undefined-handlers in chrome.dll version0.2.149.27. A crash can result without user interaction. When a user is made to visita malicious link, which has an undefined handler followed by a 'special' character,the chrome crashes with a Google Chrome message window "Whoa! Google Chrome has crashed.Restart now?". It lies in dealing with the POP EBP instruction when pointed out by theEIP register at 0x01002FF4. Proof of Concept:http://evilfingers.com/advisory/google_chrome_poc.php Credit:Rishi Narang (psy.echo)www.greyhat.inwww.evilfingers.com--------------------------------------------------- PoC Working/Exploit:Click for a demo <a href="EVIL:%">HERE</a> # milw0rm.com [2008-09-03]
声明:文章版权归原作者所有 部分文章转自互联网 如有侵权请联系 [邮箱地址] 删除

路过

雷人

握手

鲜花

鸡蛋

最新评论

返回顶部