Skip to main content

Google Chrome Multiple Vulnerabilities

Last Update Date: 25 Nov 2014 Release Date: 20 Nov 2014 3248 Views

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities have been identified in Google Chrome, which can be exploited by malicious people to disclose potentially sensitive information, conduct spoofing attacks, bypass certain security restrictions, and compromise a user's system.

  1. An unspecified error can be exploited to spoof the address bar.
  2. A use-after-free error exists in pdfium, pepper plugins and blink.
  3. An integer overflow error exists in pdfium and media.
  4. An unspecified error in pdfium and Skia can be exploited to cause a buffer overflow.
  5. An error when handling intents without BROWSABLE category can be exploited to navigate to otherwise restricted intents.
  6. The application bundles a vulnerable version of Adobe Flash Player.
  7. An error in Skia can be exploited to read uninitialized memory.

Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • Versions prior to 39.0.2171.65

    Solutions

    Before installation of the software, please visit the software manufacturer web-site for more details.

    • Upgrade to version 39.0.2171.65.

    Vulnerability Identifier


    Source


    Related Link