SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Web Browser)  >   Google Chrome Vendors:   Google
Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1026654
SecurityTracker URL:  http://securitytracker.com/id/1026654
CVE Reference:   CVE-2011-3953, CVE-2011-3954, CVE-2011-3955, CVE-2011-3956, CVE-2011-3957, CVE-2011-3958, CVE-2011-3959, CVE-2011-3960, CVE-2011-3961, CVE-2011-3962, CVE-2011-3963, CVE-2011-3964, CVE-2011-3965, CVE-2011-3966, CVE-2011-3967, CVE-2011-3968, CVE-2011-3969, CVE-2011-3970, CVE-2011-3971, CVE-2011-3972   (Links to External Site)
Date:  Feb 9 2012
Impact:   Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): prior to 17.0.963.46
Description:   Multiple vulnerabilities were reported in Google Chrome. A remote user can cause arbitrary code to be executed on the target user's system.

A remote user can create a specially crafted content that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.

Clipboard monitoring after a paste event may disclose information [CVE-2011-3953]. Daniel Cheng reported this vulnerability.

Excessive database usage can cause a crash [CVE-2011-3954]. Collin Payne reported this vulnerability.

Aborting an IndexDB transaction can cause a crash [CVE-2011-3955]. David Grogan reported this vulnerability.

Sandboxed origins inside extensions are not properly handled [CVE-2011-3956]. Devdatta Akhawe, UC Berkeley, reported this vulnerability.

A use-after-free may occur during PDF garbage collection [CVE-2011-3957]. Aki Helin of OUSPG reported this vulnerability.

An incorrect cast may occur related to column span processing [CVE-2011-3958]. miaubiz reported this vulnerability.

A buffer overflow may occur in locale handling [CVE-2011-3959]. Aki Helin of OUSPG reported this vulnerability.

An out-of-bounds read may occur in audio decoding [CVE-2011-3960]. Aki Helin of OUSPG reported this vulnerability.

Race condition may occur after a crash of utility process [CVE-2011-3961]. Shawn Goertzen reported this vulnerability.

An out-of-bounds read may occur in path clipping [CVE-2011-3962]. Aki Helin of OUSPG reported this vulnerability.

An out-of-bounds read may occur in PDF fax image handling [CVE-2011-3963]. Atte Kettunen of OUSPG reported this vulnerability.

Some "URL bar confusion" may occur after a drag and drop operation [CVE-2011-3964]. Code Audit Labs of VulnHunt.com reported this vulnerability.

A crash may occur in signature check [CVE-2011-3965]. Slawomir Blazek reported this vulnerability.

A use-after-free may occur in stylesheet error handling [CVE-2011-3966]. Aki Helin of OUSPG reported this vulnerability.

A crash may occur with an "unusual" certificate [CVE-2011-3967]. Ben Carrillo reported this vulnerability.

A use-after-free may occur in CSS handling [CVE-2011-3968]. Arthur Gerkis reported this vulnerability.

A use-after-free may occur in SVG layout [CVE-2011-3969]. Arthur Gerkis reported this vulnerability.

An out-of-bounds read may occur in libxslt [CVE-2011-3970]. Aki Helin of OUSPG reported this vulnerability.

A use-after-free may occur with mousemove events [CVE-2011-3971]. Arthur Gerkis reported this vulnerability.

An out-of-bounds read may occur in shader translator [CVE-2011-3972]. Google Chrome Security Team (Inferno) reported this vulnerability.

Impact:   A remote user can create HTML that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution:   The vendor has issued a fix (17.0.963.46).

The vendor's advisory is available at:

http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html

Vendor URL:  googlechromereleases.blogspot.com/2012/02/stable-channel-update.html (Links to External Site)
Cause:   Access control error, Boundary error, State error
Underlying OS:  Linux (Any), UNIX (macOS/OS X), Windows (Any)

Message History:   This archive entry has one or more follow-up message(s) listed below.
Sep 13 2012 (Red Hat Issues Fix for libxslt) Google Chrome Multiple Flaws Let Remote Users Execute Arbitrary Code
Red Hat has issued a fix for libxslt for Red Hat Enterprise Linux 5 and 6.



 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2021, SecurityGlobal.net LLC