Google Chrome Multiple Vulnerabilities
Last Update Date:
14 Nov 2013 10:50
Release Date:
14 Nov 2013
3982
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to conduct spoofing attacks, disclose potentially sensitive information, and compromise a user's system.
- A use-after-free error exists in speech input elements.
- A use-after-free error exists in media elements.
- An out-of-bounds read error exists in SVG.
- A use-after-free error exists in "id" attribute strings.
- A use-after-free error exists in DOM ranges.
- An error related to interstitial warnings can be exploited to spoof contents of the address bar.
- An out-of-bounds read error exists in HTTP parsing.
- An error exists due to not checking certificates during TLS renegotiation.
- Some unspecified errors exist.
- A use-after-free error exists in libjingle.
Impact
- Remote Code Execution
- Information Disclosure
- Spoofing
System / Technologies affected
- Google Chrome 30.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 31.0.1650.48.
Vulnerability Identifier
- CVE-2013-2931
- CVE-2013-6621
- CVE-2013-6622
- CVE-2013-6623
- CVE-2013-6624
- CVE-2013-6625
- CVE-2013-6626
- CVE-2013-6627
- CVE-2013-6628
- CVE-2013-6629
- CVE-2013-6630
- CVE-2013-6631
Source
Related Link
Share with