CERT-In Advisory
CIAD-2014-0058
Multiple Vulnerabilities in Google Chrome
Original Issue Date: October 13, 2014
Severity Rating: High
Systems Affected
- Google Chrome prior to version 38.0.2125.101
Overview
Multiple vulnerabilities have been reported in Google Chrome which could be exploited by remote attackers to disclose potentially sensitive information and bypass certain security restrictions on a targeted user's system.
Description
Multiple vulnerabilities have been reported in Google Chrome, which are caused due to use-after-free error within Events, Rendering, DOM and Web Workers. Some flaws in V8 engine and IPC are vulnerable to arbitrary code execution outside the sandbox [CVE-2014-3188]. PDFium is vulnerable to out-of-bounds read access [CVE-2014-3189], [CVE-2014-3198]. A type confusion error has been reported in Session Management [CVE-2014-3193]. An error reported within V8 engine [CVE-2014-3195] and XSS Auditor [CVE-2014-3197] which is vulnerable to information leak. An error reported which could be exploited to bypass permissions in windows sandbox [CVE-2014-3196]. An error has been reported within V8 bindings which could be exploited to cause a Release Assert in V8 bindings [CVE-2014-3199]. A use-after-free vulnerability reported in Events [CVE-2014-3190]. A use-after-free reported in rendering [CVE-2014-3191]. A use-after-free vulnerability reported in DOM [CVE-2014-3192] and Web Workers [CVE-2014-3194] some unspecified errors/flaws also exist [CVE-2014-3200] and multiple unspecified vulnerabilities reported in Google V8 [CVE-2014-7967] which could cause a denial of service or possibly have other impact via unknown vectors.
Remote attackers could exploit these vulnerabilities via multiple vectors. Successful exploitation of these vulnerabilities could allow remote attackers to disclose potentially sensitive information and bypass certain security restrictions on the targeted user's system.
Solution
Upgrade to Google Chrome latest version 38.0.2125.101 from Google.
https://www.google.com/chrome/browser/
Vendor Information
Google Chrome
http://googlechromereleases.blogspot.in/2014/10/stable-channel-update.html
References
Google Chrome
http://googlechromereleases.blogspot.in/2014/10/stable-channel-update.html
SecurityFocus
http://www.securityfocus.com/bid/70262
http://www.securityfocus.com/bid/70273
SecurityTracker
http://www.securitytracker.com/id/1030980
CVE Name
CVE-2014-3188
CVE-2014-3189
CVE-2014-3190
CVE-2014-3191
CVE-2014-3192
CVE-2014-3193
CVE-2014-3194
CVE-2014-3195
CVE-2014-3196
CVE-2014-3197
CVE-2014-3198
CVE-2014-3199
CVE-2014-3200
CVE-2014-7967
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|