[PCWorks] Google Chrome Multiple Vulnerabilities

  • From: "Clint Hamilton-PCWorks Admin" <PCWorks@xxxxxxxxxxxxxxxxxxxxxxxx>
  • To: "PCWorks@xxxxxxxxxxxxx" <pcworks@xxxxxxxxxxxxx>
  • Date: Wed, 6 Mar 2013 07:44:49 -0600

TITLE:
Google Chrome Multiple Vulnerabilities

Criticality level: Highly critical
Impact: System access
Where: From remote

Software:  Google Chrome 25.x

SECUNIA ADVISORY ID:
http://secunia.com/advisories/52454/

DESCRIPTION:
Multiple vulnerabilities have been reported in Google Chrome,
where
some have an unknown impact and others can be exploited by
malicious
people to compromise a user's system.

1) A use-after-free error exists in frame loader.

2) A use-after-free error exists in browser navigation
handling.

3) An error in Web Audio can be exploited to cause memory
corruption.

4) A use-after-free error exists in SVG animations.

5) An error in Indexed DB can be exploited to cause memory
corruption.

6) A race condition error exists in media thread handling.

7) An error exists during handling of bindings for extension
processes.

8) An error exists when loading browser plug-in.

9) A path traversal error exists when handling database.

The vulnerabilities are reported in versions prior to
25.0.1364.152.

SOLUTION:
Update to version 25.0.1364.152.

ORIGINAL ADVISORY:
http://googlechromereleases.blogspot.dk/2013/03/stable-channel-update_4.html


=========================
The list's FAQ's can be seen by sending an email to 
PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line.

To unsubscribe, subscribe, set Digest or Vacation to on or off, go to 
//www.freelists.org/list/pcworks .  You can also send an email to 
PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line.  Your 
member list settings can be found at 
//www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks .  Once logged in, you have 
access to numerous other email options.  

The list archives are located at //www.freelists.org/archives/pcworks/ .  
All email posted to the list will be placed there in the event anyone needs to 
look for previous posts.
-zxdjhu-

Other related posts: