CERT-In Advisory
CIAD-2012-0049
Multiple Vulnerabilities in Google Chrome
Original Issue Date: October 16, 2012
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 22.0.1229.92
Overview
Multiple vulnerabilities have been reported in the Google Chrome versions prior to 22.0.1229.92, which could be exploited by remote attackers to execute arbitrary code to take control of the affected system.
Description
Multiple vulnerabilities have been reported in the Google Chrome due to Crash in Skia text rendering, race condition in audio device handling, out-of-bounds read in compositor & in ICU regex processing and pepper plug-ins do not perform crash monitoring.
Successful exploitation of these vulnerabilities could allow the remote attacker to execute arbitrary code to take control of the affected system.
Solution
Apply appropriate patches as mentioned :
http://googlechromereleases.blogspot.in/2012/10/stable-channel-update.html
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.in/2012/10/stable-channel-update.html
References
Security Tracker
http://securitytracker.com/id/1027617
Security Focus
http://www.securityfocus.com/bid/55830
CVE Name
CVE-2012-2900
CVE-2012-5108
CVE-2012-5109
CVE-2012-5110
CVE-2012-5111
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|