CERT-In Advisory
CIAD-2011-0064
Multiple Vulnerabilities in Google Chrome
Original Issue Date: November 17, 2011
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 15.0.874.120
Overview
Multiple vulnerabilities have been reported in the Google Chrome, which could be exploited by remote attackers to cause a Denial of Service(DoS) condition or execute arbitrary code to take control of the affected systems.
Description
Multiple vulnerabilities have been reported in the Google Chrome due to double-free memory error, out-of-bounds memory read error, memory corruption error, heap overflow, buffer overflow, use-after-free error and Failure to ask for permission to run applets in JRE7.
Successful exploitation of these vulnerabilities through specially crafted file could allow a malicious remote attacker to cause a Denial of Service(DoS) condition or execute arbitrary code to take a control of the affected system.
Solution
Apply appropriate patches as mentioned :
http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.html
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.com/2011/11/stable-channel-update.html
References
Security Tracker
http://securitytracker.com/id/1026313
CVE Name
CVE-2011-3892
CVE-2011-3893
CVE-2011-3894
CVE-2011-3895
CVE-2011-3896
CVE-2011-3897
CVE-2011-3898
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|