[PCWorks] Google Chrome Multiple Vulnerabilities

  • From: "Clint Hamilton-PCWorks Admin" <PCWorks@xxxxxxxxxxxxxxxxxxxxxxxx>
  • To: "PCWorks@xxxxxxxxxxxxx" <pcworks@xxxxxxxxxxxxx>
  • Date: Thu, 8 Nov 2012 04:38:46 -0600

TITLE:
Google Chrome Multiple Vulnerabilities

Criticality level:  Highly critical
Impact:  Security Bypass, System access
Where:  From remote

Software:  Google Chrome 22.x

SECUNIA ADVISORY ID:
http://secunia.com/advisories/51210/

DESCRIPTION:
Multiple vulnerabilities have been reported in Google Chrome, 
which
can be exploited by malicious people to bypass certain security
restrictions and compromise a user's system.

1) The application bundles a vulnerable version of Adobe Flash
Player.

For more information:
http://secunia.com/SA51213/

2) An integer overflow error exists in WebP handling.

3) An error in v8 can be exploited to cause an out-of-bounds 
array
access.

4) A use-after-free error exists in SVG filter handling.

5) An error exists related to integer boundary checks within 
GPU
command buffers.

6) A use-after-free error exists in video layout handling.

7) An error exists related to inappropriate loading of SVG
subresource in "img" context.

8) A race condition error exists in Pepper buffer handling.

9) A type casting error exists in certain input handling.

10) An error in Skia can be exploited to cause an out-of-bounds
read.

11) An error in texture handling can be exploited to corrupt 
memory.

12) A use-after-free error exists in extension tab handling.

13) A use-after-free error exists in plug-in placeholder 
handling.

14) An error in v8 can be exploited to corrupt memory.

SOLUTION:
Upgrade to version 23.0.1271.64.

ORIGINAL ADVISORY:
Google:
http://googlechromereleases.blogspot.dk/2012/11/stable-channel-release-and-beta-channel.html


=========================
The list's FAQ's can be seen by sending an email to 
PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line.

To unsubscribe, subscribe, set Digest or Vacation to on or off, go to 
//www.freelists.org/list/pcworks .  You can also send an email to 
PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line.  Your 
member list settings can be found at 
//www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks .  Once logged in, you have 
access to numerous other email options.  

The list archives are located at //www.freelists.org/archives/pcworks/ .  
All email posted to the list will be placed there in the event anyone needs to 
look for previous posts.
-zxdjhu-

Other related posts: