Google Chrome Multiple Vulnerabilities
Last Update Date:
15 Dec 2011 10:39
Release Date:
15 Dec 2011
5517
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, and compromise a user's system.
- An error in regex matching, libxml, PDF parser, SVG parsing, handling YUV video frames, and handling PDF and PDF cross references can be exploited to cause an out-of-bounds read.
- An error in the view-source functionality can be exploited to spoof a URL bar.
- An error when handling a CSS property array can be exploited to corrupt memory (only the 64-bit platforms affected).
- A use-after-free error exists in SVG filters, range handling and bidi handling.
- An error within v8 i18n handling can be exploited to cause an out-of-bounds write.
- An error when handling certain PDF fonts can be exploited to cause a buffer overflow.
- An error in FileWatcher can be exploited to cause a stack-based buffer overflow.
Impact
- Remote Code Execution
- Information Disclosure
- Spoofing
System / Technologies affected
- Google Chrome 15.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 16.0.912.63.
Vulnerability Identifier
- CVE-2011-3903
- CVE-2011-3904
- CVE-2011-3905
- CVE-2011-3906
- CVE-2011-3907
- CVE-2011-3908
- CVE-2011-3909
- CVE-2011-3910
- CVE-2011-3911
- CVE-2011-3912
- CVE-2011-3913
- CVE-2011-3914
- CVE-2011-3915
- CVE-2011-3916
- CVE-2011-3917
Source
Related Link
Share with