| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.800567 |
| Category: | Buffer overflow |
| Title: | Google Chrome Buffer Overflow Vulnerability |
| Summary: | Check for the version of Google Chrome |
| Description: | Overview: The host is installed with Google Chrome and is prone to Buffer Overflow vulnerability. Vulnerability Insight: These flaws are due to, - a boundary error in nitSkBitmapFromData() function while processing vectors related to large bitmap that arrives over the IPC channel. - a failure while validating the result of integer multiplication when computing image sizes. Impact: Successful exploitation will let the attacker run arbitrary codes with the privilege of logged on user or can craft a special images or canvas to execute arbitrary code inside the sandboxed renderer (tab) process and cause a tab to crash. Impact level: Application Affected Software/OS: Google Chrome versions prior to 1.0.154.64, version 2.0.159.0 and prior. Fix: Upgrade to version 1.0.154.64 http://www.google.com/chrome References: http://code.google.com/p/chromium/issues/detail?id=10869 http://googlechromereleases.blogspot.com/2009/05/stable-update-security-fix.html |
| Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1441 BugTraq ID: 34859 http://www.securityfocus.com/bid/34859 http://osvdb.org/54288 http://www.securitytracker.com/id?1022174 http://secunia.com/advisories/35014 http://www.vupen.com/english/advisories/2009/1266 XForce ISS Database: chrome-paramtraitsskbitmapread-bo(50362) http://xforce.iss.net/xforce/xfdb/50362 Common Vulnerability Exposure (CVE) ID: CVE-2009-1442 http://osvdb.org/54248 http://www.securitytracker.com/id?1022175 |
| Copyright | Copyright (C) 2009 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|