Google Chrome Multiple Vulnerabilities
Last Update Date:
25 Nov 2014
Release Date:
20 Nov 2014
3799
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system.
- An unspecified error can be exploited to spoof the address bar.
- A use-after-free error exists in pdfium, pepper plugins and blink.
- An integer overflow error exists in pdfium and media.
- An unspecified error in pdfium and Skia can be exploited to cause a buffer overflow.
- An error when handling intents without BROWSABLE category can be exploited to navigate to otherwise restricted intents.
- The application bundles a vulnerable version of Adobe Flash Player.
- An error in Skia can be exploited to read uninitialized memory.
Impact
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Spoofing
System / Technologies affected
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to version 39.0.2171.65.
Vulnerability Identifier
- CVE-2014-0574
- CVE-2014-7899
- CVE-2014-7900
- CVE-2014-7901
- CVE-2014-7902
- CVE-2014-7903
- CVE-2014-7904
- CVE-2014-7905
- CVE-2014-7906
- CVE-2014-7907
- CVE-2014-7908
- CVE-2014-7909
- CVE-2014-7910
Source
Related Link
Share with