Summary
This host is installed with Google Chrome and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to inject scripts, bypass certain security restrictions, execute arbitrary code in the context of the browser or cause a denial of service.
Impact Level: System/Application
Solution
Upgrade to the Google Chrome 18.0.1025.151 or later, For updates refer to http://www.google.com/chrome
Insight
The flaws are due to
- Unspecified errors in flash player, allows to corrupt memory in the chrome interface.
- An out of bounds read error when handling skia clipping.
- Errors in the cross origin policy when handling iframe replacement and parenting pop up windows.
- Multiple use after free errors when handling line boxes, v8 bindings, HTMLMediaElement, SVG resources, media content, focus events and when applying style commands.
- A read after free error in the script bindings.
Affected
Google Chrome version prior to 18.0.1025.151 on Mac OS X
References
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 Feb13 (Windows)
- Adobe Flash Media Server multiple vulnerabilities
- Adobe Acrobat Multiple Unspecified Vulnerabilities-01 Sep13 (Mac OS X)
- Adobe Flash Player 'SWF' File Multiple Code Execution Vulnerability - Mac OS X
- Adobe Air Multiple Vulnerabilities June-2012 (Mac OS X)