CERT-In Advisory
CIAD-2011-0070
Multiple Vulnerabilities in Google Chrome
Original Issue Date: December 21, 2011
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 16.0.912.63
Overview
Multiple vulnerabilities have been reported in the Google Chrome, which could be exploited by remote attackers to execute arbitrary code to take control of the affected systems.
Description
Multiple vulnerabilities have been reported in the Google Chrome due to error in out-of-bounds, view-source functionality, memory corruption, use-after-free, buffer overflow.
Successful exploitation of these vulnerabilities could allow a remote attacker to spoof the URL bar, cause denial of service(DoS) condition or execute arbitrary code to take a control of the affected system.
Solution
Upgrade to Google Chrome version 16.0.912.63.
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.com/2011/12/stable-channel-update.html
References
Security Focus
http://www.securityfocus.com/bid/51041/
Secunia
http://secunia.com/advisories/47231/
CVE Name
CVE-2011-3903
CVE-2011-3904
CVE-2011-3906
CVE-2011-3907
CVE-2011-3908
CVE-2011-3909
CVE-2011-3910
CVE-2011-3911
CVE-2011-3912
CVE-2011-3913
CVE-2011-3914
CVE-2011-3915
CVE-2011-3916
CVE-2011-3917
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|