CERT-In Advisory
CIAD-2013-0083
Multiple Vulnerabilities in Google Chrome
Original Issue Date: November 19, 2013
Severity Rating: High
Systems Affected
- Google Chrome prior to 31.0.1650.57
Overview
Multiple vulnerabilities have been reported in Google Chrome which could be exploited by a remote attacker to execute arbitrary code to compromise user's system, conduct spoofing attack and disclose sensitive information.
Description
Multiple vulnerabilities have been reported in Google Chrome due to use-after-free error in speech input elements, media elements, "id" attribute strings, DOM ranges and libjingle, out-of bound errors in HTTP parsing and SVG, error related to interstitial warnings, certificate validation error during TLS renegotiation, uninitialized memory reads in libjpeg and libjpeg-turbo and other unspecified errors.
Successful exploitation of these vulnerabilities could allow a remote attacker to conduct spoofing attacks, gain elevated privileges, disclose potentially sensitive information, execute arbitrary code or cause denial of service (DoS) conditions.
Solution
Upgrade to Google Chrome version 31.0.1650.57.
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.in/2013/11/stable-channel-update.html
http://googlechromereleases.blogspot.in/2013/11/stable-channel-update_14.html
References
Google Chrome
http://googlechromereleases.blogspot.in/2013/11/stable-channel-update.html
http://googlechromereleases.blogspot.in/2013/11/stable-channel-update_14.html
Secunia
http://secunia.com/advisories/55637/
Security tracker
http://www.securitytracker.com/id/1029330
CVE Name
CVE-2013-2931
CVE-2013-6621
CVE-2013-6622
CVE-2013-6623
CVE-2013-6624
CVE-2013-6625
CVE-2013-6626
CVE-2013-6627
CVE-2013-6628
CVE-2013-6629
CVE-2013-6630
CVE-2013-6631
CVE-2013-6632
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|