CERT-In Advisory
CIAD-2011-0066
Google Chrome Out-of-Bounds Write Error Remote Code Execution Vulnerability
Original Issue Date: November 23, 2011
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 15.0.874.121
Overview
A vulnerability have been reported in the Google Chrome, which could be exploited by remote attackers to cause a denial of service condition or to execute arbitrary code to take control of the affected system.
Description
This vulnerability occurs due to an out-of-bounds write error in the v8 engine in Google Chrome, which could be exploited by a remote attacker, via a specially crafted HTML file.
Successful exploitation of this vulnerability could allow a remote attacker to cause Denial of Service condition(DoS) condition or execute arbitrary code to take control of the target system.
Solution
Upgrade to Google Chrome version 15.0.874.121.
http://googlechromereleases.blogspot.com/2011/11/stable-channel-update_16.html
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.com/2011/11/stable-channel-update_16.html
References
Securityfocus
http://www.securityfocus.com/bid/50701/
SecurityTracker
http://securitytracker.com/id/1026338
CVE Name
CVE-2011-3900
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|