Google Chrome Javascript Memory Corruption Vulnerabilities
RISK: Medium Risk
Two vulnerabilities have been identified in Google Chrome, which could be exploited by remote attackers to compromise a vulnerable system.
1. A heap overflow error when evaluating a specially crafted regular expression in Javascript, which could be exploited to crash an affected browser and execute arbitrary code in the sandbox.
2. An error when allocate memory buffers for a renderer (tab) process, which could allow a compromised process (e.g. via the first issue) to cause the browser process (and all tabs) to crash or execute arbitrary code with the privileges of the logged on user, bypassing the sandbox.
Impact
- Remote Code Execution
System / Technologies affected
- Google Chrome versions prior to 2.0.172.37
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Google Chrome version 2.0.172.37 :
http://www.google.com/chromed
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with