Google Chrome Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to disclose potentially sensitive information, conduct cross-site scripting attacks, and compromise a user's system.
- A use-after-free error exists in SVG.
- A bad cast error exists in clipboard handling.
- A use-after-free error exists in media loader.
- A use-after-free error exists in Pepper resource handling.
- A use-after-free error exists in widget handling.
- A use-after-free error exists in speech handling.
- A use-after-free error exists in style resolution.
- Some memory safety issues exist in Web Audio.
- A use-after-free error exists in media loader.
- A use-after-free race condition error exists with workers.
- An unspecified error exists related to XSS Auditor, which can be exploited to extract certain data.
- An unspecified error exists related to drag and drop or copy and paste, which can be exploited to conduct cross-site scripting attacks.
Successful exploitation of the vulnerabilities #1 through #7, #9, and #10 may allow execution of arbitrary code. Some vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash.
Impact
- Cross-Site Scripting
- Information Disclosure
System / Technologies affected
- Google Chrome 26.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 27.0.1453.93.
Vulnerability Identifier
- CVE-2013-2728
- CVE-2013-2836
- CVE-2013-2837
- CVE-2013-2839
- CVE-2013-2840
- CVE-2013-2841
- CVE-2013-2842
- CVE-2013-2843
- CVE-2013-2844
- CVE-2013-2845
- CVE-2013-2846
- CVE-2013-2847
- CVE-2013-2848
- CVE-2013-2849
- CVE-2013-3324
- CVE-2013-3325
- CVE-2013-3326
- CVE-2013-3327
- CVE-2013-3328
- CVE-2013-3329
- CVE-2013-3330
- CVE-2013-3331
- CVE-2013-3332
- CVE-2013-3333
- CVE-2013-3334
- CVE-2013-3335
Source
Related Link
Share with