Google Chrome Multiple Vulnerabilities
Last Update Date:
25 Feb 2013 15:59
Release Date:
25 Feb 2013
4397
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
- An unspecified error related to web audio node can be exploited to corrupt memory.
- A use-after-free error exists in database handling.
- An unspecified error exists in Matroska Handling.
- An unspecified error exists related to excessive SVG parameters.
- An unspecified error exists in Skia.
- An unspecified error exists due to inappropriate load of NaCl.
- An unspecified error exists due to incorrect NaCl signal handling. (Note: This vulnerability affects the Mac platform only.)
- An error exists due to the developer tools process having to many permissions and incorrectly placing too much trust in the connected server.
- An out-of-bounds read error exists in Skia.
- Some unspecified errors exist due to memory safety issues across the IPC layer.
- An integer overflow error exists in blob handling.
- Some unspecified errors exist related to IPC layer.
- A race condition error exists in media handling.
- An error related to vorbis decoding can be exploited to cause a buffer overflow.
- An unspecified error exists due to incorrect path handling in file copying. (Note: This vulnerability affects the Linux and Mac platforms only.)
- Some unspecified errors exist within the memory management in plug-in message handling.
- A use-after-free error exists in URL handling.
- An integer overflow error exists in Opus handling.
- A race condition error exists in ICU.
- An unspecified error exists in the WebKit implementation of MathML.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Google Chrome 24.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 25.0.1364.97 for Windows and Linux and 25.0.1364.99 for Mac.
Vulnerability Identifier
- CVE-2013-0879
- CVE-2013-0880
- CVE-2013-0881
- CVE-2013-0882
- CVE-2013-0883
- CVE-2013-0884
- CVE-2013-0885
- CVE-2013-0886
- CVE-2013-0887
- CVE-2013-0888
- CVE-2013-0889
- CVE-2013-0890
- CVE-2013-0891
- CVE-2013-0892
- CVE-2013-0893
- CVE-2013-0894
- CVE-2013-0895
- CVE-2013-0896
- CVE-2013-0897
- CVE-2013-0898
- CVE-2013-0899
- CVE-2013-0900
Source
Related Link
Share with