CERT-In Advisory
CIAD-2013-0086
Multiple Vulnerabilities in Google Chrome
Original Issue Date: December 10, 2013
Severity Rating: High
Systems Affected
- Google Chrome versions prior to 31.0.1650.63
Overview
Multiple vulnerabilities have been reported in the Google Chrome, which could be exploited by remote attackers to conduct spoofing attacks, session fixation attacks, execute arbitrary code and cause Denial of Service(DoS) condition.
Description
Multiple vulnerabilities have been reported in the Google Chrome due to various errors such as error when handling the 302 HTTP status in syncin OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc, Use-after-free error in CompositeEditCommand.cpp and ReplaceSelectionCommand.cpp, error in checking for an empty document during presentation of a modal dialog in FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp, multiple buffer overflow errors in runtime.cc in Google V8 and error in DehoistArrayIndex function in hydrogen-dehoist.cc in Google V8. A remote attacker could exploit these vulnerabilities via specially crafted large typed array, a crafted index and various other vectors.
Successful exploitation of these vulnerabilities could allow the remote attacker to conduct spoofing attacks, session fixation attacks, execute arbitrary code and cause a Denial of Service(DoS) condition.
Solution
Upgrade to Google chrome version 31.0.1650.63
http://www.google.com/chrome
Vendor Information
Google Chrome
http://www.google.com/chrome
http://googlechromereleases.blogspot.in/2013/12/stable-channel-update.html
References
Secunia
http://secunia.com/advisories/55942/
Security Focus
http://www.securityfocus.com/bid/64078
SecurityTracker
http://securitytracker.com/id/1029442
CVE Name
CVE-2013-6634
CVE-2013-6635
CVE-2013-6636
CVE-2013-6637
CVE-2013-6638
CVE-2013-6639
CVE-2013-6640
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|