[PCWorks] Google Chrome Multiple Vulnerabilities

  • From: "Clint Hamilton-PCWorks Admin" <PCWorks@xxxxxxxxxxxxxxxxxxxxxxxx>
  • To: "PCWorks@xxxxxxxxxxxxx" <pcworks@xxxxxxxxxxxxx>
  • Date: Thu, 27 Sep 2012 03:28:18 -0500

TITLE:
Google Chrome Multiple Vulnerabilities

Criticality level:  Highly critical
Impact:  Cross Site Scripting, System access
Where:  From remote

Software:  Google Chrome 21.x

SECUNIA ADVISORY ID:
50447

DESCRIPTION:
Multiple vulnerabilities have been reported in Google Chrome,
where some have an unknown impact and others can be exploited
by malicious people to conduct cross-site scripting attacks and
compromise a user's system.

1) An out-of-bounds read error exists when handling line
breaks.

2) A bad cast error exists within run-ins.

3) A race condition error exists when handling XMLHttpRequest
calls.

4) An error when loading URLs can be exploited to cause a stale
buffer.

5) A bad cast error exists when handling XSL transforms.

6) An error when handling certain SSL data can be exploited to
cause a cross-site scripting attack.

The vulnerabilities are reported in versions prior to
21.0.1180.89.

SOLUTION:
Update to version 21.0.1180.89.

ORIGINAL ADVISORY:
http://googlechromereleases.blogspot.com/2012/08/stable-channel-update_30.html

=========================
The list's FAQ's can be seen by sending an email to 
PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line.

To unsubscribe, subscribe, set Digest or Vacation to on or off, go to 
//www.freelists.org/list/pcworks .  You can also send an email to 
PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line.  Your 
member list settings can be found at 
//www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks .  Once logged in, you have 
access to numerous other email options.  

The list archives are located at //www.freelists.org/archives/pcworks/ .  
All email posted to the list will be placed there in the event anyone needs to 
look for previous posts.
-zxdjhu-

Other related posts: