Skip to main content

Google Chrome Multiple Vulnerabilities

Last Update Date: 6 Dec 2013 11:33 Release Date: 6 Dec 2013 3043 Views

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct spoofing and session fixation attacks and compromise a user's system.

  1. An error when handling the 302 HTTP status in sync can be exploited to conduct session fixation attacks.
  2. A use-after-free error exists in editing.
  3. An error related to modal dialogs can be exploited to spoof the contents of the address bar.
  4. Some unspecified errors exist.
  5. An unspecified error in v8 can be exploited to cause a buffer overflow.
  6. An out-of-bounds write error exists in v8.
  7. An out-of-bounds read error exists in v8.

Successful exploitation of the vulnerabilities #2, #5, and #6 may allow execution of arbitrary code.


Impact

  • Spoofing
  • LAN Based Remote Code Execution

System / Technologies affected

  • Versions prior to 31.0.1650.63.

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 31.0.1650.63.

Vulnerability Identifier


Source


Related Link