CERT-In Advisory
CIAD-2012-0045
Multiple Vulnerabilities in Google Chrome
Original Issue Date: October 04, 2012
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 22.0.1229.79
Overview
Multiple vulnerabilities have been reported in the Google Chrome versions prior to 22.0.1229.79 for Mac, Windows, and Linux, which could be exploited by remote attackers to execute arbitrary code, steal cookie-based authentication credentials or cause a denial of service condition to take control of the affected system.
Description
Multiple vulnerabilities have been reported in the Google Chrome due to windows kernel memory corruption, UXSS in frame handling & v8 bindings, DOM tree corruption with plug-ins, Buffer overflow in SSE2 optimizations, Out-of-bounds write in Skia, Use-after-free in onclick handling & in SVG text references & in plug-in handling & in PDF viewer, Crash in graphics context handling, Integer overflow in WebGL, Browser crash with extensions and modal dialogs, DOM topology corruption, Race condition in plug-in paint buffer, Wild pointer in OGG container handling, Address leak over IPC, Pop-up block bypass, Double free in XSL transforms.
Successful exploitation of these vulnerabilities could allow the remote attacker to execute arbitrary code to take control of the affected system or cause a denial of service condition.
Solution
Apply appropriate patches as mentioned :
http://googlechromereleases.blogspot.in/2012/09/stable-channel-update_25.html
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.in/2012/09/stable-channel-update_25.html
References
Security Focus
http://www.securityfocus.com/bid/55676/
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=27052
CVE Name
CVE-2012-2874
CVE-2012-2875
CVE-2012-2876
CVE-2012-2877
CVE-2012-2878
CVE-2012-2879
CVE-2012-2880
CVE-2012-2882
CVE-2012-2883
CVE-2012-2884
CVE-2012-2885
CVE-2012-2886
CVE-2012-2887
CVE-2012-2888
CVE-2012-2889
CVE-2012-2890
CVE-2012-2891
CVE-2012-2892
CVE-2012-2893
CVE-2012-2894
CVE-2012-2895
CVE-2012-2896
CVE-2012-2897
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|