Google Chrome Multiple Vulnerabilities
Last Update Date:
6 Dec 2013 11:33
Release Date:
6 Dec 2013
3631
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to conduct spoofing and session fixation attacks and compromise a user's system.
- An error when handling the 302 HTTP status in sync can be exploited to conduct session fixation attacks.
- A use-after-free error exists in editing.
- An error related to modal dialogs can be exploited to spoof the contents of the address bar.
- Some unspecified errors exist.
- An unspecified error in v8 can be exploited to cause a buffer overflow.
- An out-of-bounds write error exists in v8.
- An out-of-bounds read error exists in v8.
Successful exploitation of the vulnerabilities #2, #5, and #6 may allow execution of arbitrary code.
Impact
- Spoofing
- LAN Based Remote Code Execution
System / Technologies affected
- Versions prior to 31.0.1650.63.
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 31.0.1650.63.
Vulnerability Identifier
Source
Related Link
Share with