HTTP: Google Chrome CVE-2016-1677 Information Disclosure

This signature detects attempts to exploit a known vulnerability against Google Chrome. A successful attack can lead to information disclosure.

Extended Description

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

Affected Products

Google v8

References

CVE: CVE-2016-1677

Short Name
HTTP:STC:CHROME:CVE-2016-1677
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2016-1677 Chrome Disclosure Google Information
Release Date
05/11/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Google

Suse

Redhat

Opensuse

Debian

Canonical

CVSS Score

4.3

Found a potential security threat?