Google Chrome WebKit Memory Corruption and Information Disclosure Vulnerabilities
RISK: Medium Risk
Two vulnerabilities have been reported in Google Chrome, which can be exploited by attackers to disclose sensitive information or compromise an affected system.
1. An error in WebKit when handling recursion in certain DOM event handlers can be exploited to corrupt memory and potentially execute arbitrary code.
2. An error in WebKit when handling drag events can be exploited to disclose sensitive information when content is dragged over a malicious web page.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Google Chrome versions prior to 2.0.172.31
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Google Chrome version 2.0.172.31:
http://www.google.com/chrome
Vulnerability Identifier
Source
Share with