SB2011102505 - Multiple vulnerabilities in Techland Chrome
Published: October 25, 2011 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 15 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2011-3875)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Google Chrome before 15.0.874.102 does not properly handle drag and drop operations on URL strings, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
2) Input validation error (CVE-ID: CVE-2011-3876)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Google Chrome before 15.0.874.102 does not properly handle downloading files that have whitespace characters at the end of a filename, which has unspecified impact and user-assisted remote attack vectors.
3) Race condition (CVE-ID: CVE-2011-3878)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Race condition in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to worker process initialization.
4) Input validation error (CVE-ID: CVE-2011-3879)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Google Chrome before 15.0.874.102 does not prevent redirects to chrome: URLs, which has unspecified impact and remote attack vectors.
5) Input validation error (CVE-ID: CVE-2011-3880)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Google Chrome before 15.0.874.102 does not prevent use of an unspecified special character as a delimiter in HTTP headers, which has unknown impact and remote attack vectors.
6) Use-after-free (CVE-ID: CVE-2011-3882)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors related to media buffers. A remote attackers can cause a denial of service or possibly have unspecified other impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
7) Use-after-free (CVE-ID: CVE-2011-3883)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors related to counters. A remote attackers can cause a denial of service or possibly have unspecified other impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
8) Input validation error (CVE-ID: CVE-2011-3884)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Google Chrome before 15.0.874.102 does not properly address timing issues during DOM traversal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
9) Use-after-free (CVE-ID: CVE-2011-3885)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors related to stale Cascading Style Sheets (CSS) token-sequence data. A remote attackers can cause a denial of service or possibly have unspecified other impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
10) Reliance on Cookies without Validation and Integrity Checking (CVE-ID: CVE-2011-3887)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote attackers to bypass intended access restrictions and read cookies via unspecified vectors.
11) Use-after-free (CVE-ID: CVE-2011-3888)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors related to editing operations in conjunction with an unknown plug-in. A user-assisted remote attackers can cause a denial of service or possibly have unspecified other impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
12) Heap-based buffer overflow (CVE-ID: CVE-2011-3889)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the Web Audio implementation in Google Chrome before 15.0.874.102. A remote attacker can use unknown vectors. to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
13) Use-after-free (CVE-ID: CVE-2011-3890)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing vectors related to video source handling. A remote attackers can cause a denial of service or possibly have unspecified other impact.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
14) Input validation error (CVE-ID: CVE-2011-3891)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Google Chrome before 15.0.874.102 does not properly restrict access to internal Google V8 functions, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
15) Input validation error (CVE-ID: CVE-2011-2845)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.
Remediation
Install update from vendor's website.
References
- http://code.google.com/p/chromium/issues/detail?id=88949
- http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70953
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12275
- http://code.google.com/p/chromium/issues/detail?id=90217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70954
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13042
- http://code.google.com/p/chromium/issues/detail?id=94487
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70956
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12811
- http://code.google.com/p/chromium/issues/detail?id=95374
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70957
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13246
- http://code.google.com/p/chromium/issues/detail?id=95992
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70958
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12672
- http://code.google.com/p/chromium/issues/detail?id=96292
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70960
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13266
- http://code.google.com/p/chromium/issues/detail?id=96902
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70961
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13091
- http://code.google.com/p/chromium/issues/detail?id=97148
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70962
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13196
- http://code.google.com/p/chromium/issues/detail?id=100059
- http://code.google.com/p/chromium/issues/detail?id=97599
- http://code.google.com/p/chromium/issues/detail?id=98064
- http://code.google.com/p/chromium/issues/detail?id=98556
- http://code.google.com/p/chromium/issues/detail?id=99294
- http://code.google.com/p/chromium/issues/detail?id=99880
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00000.html
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00001.html
- http://lists.apple.com/archives/security-announce/2012/Mar/msg00003.html
- http://secunia.com/advisories/48274
- http://secunia.com/advisories/48288
- http://secunia.com/advisories/48377
- http://www.securitytracker.com/id?1026774
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70963
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73804
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13216
- http://code.google.com/p/chromium/issues/detail?id=98407
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70965
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13179
- http://code.google.com/p/chromium/issues/detail?id=99138
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70966
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73805
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13107
- http://code.google.com/p/chromium/issues/detail?id=99211
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70967
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12860
- http://code.google.com/p/chromium/issues/detail?id=99553
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70968
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12286
- http://code.google.com/p/chromium/issues/detail?id=100322
- https://exchange.xforce.ibmcloud.com/vulnerabilities/70969
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13172
- http://code.google.com/p/chromium/issues/detail?id=86758
- http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html
- http://support.apple.com/kb/HT5400
- http://support.apple.com/kb/HT5503
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13044