Summary
This host is installed with Google Chrome and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow remote attackers to cause a denial of service, cross-site-scripting and execution of arbitrary code.
Impact Level: Application
Solution
Upgrade to Google Chrome version 5.0.375.70 or later, For updates refer to http://www.google.com/chrome
Insight
The flaws are due to:
- Error in 'toAlphabetic' function in 'rendering/RenderListMarker.cpp' in WebCore in WebKit.
- Error in 'page/Geolocation.cpp' which does stop timers associated with geolocation upon deletion of a document.
- Memory corruption in 'font' handling.
- Error in 'editing/markup.cpp' which fails to validate input passed to 'innerHTML' property of textarea.
- Error in 'third_party/WebKit/WebCore/dom/Element.cpp' in 'Element::normalizeAttributes()' resulting in DOM mutation events being fired.
- 'Clipboard::DispatchObject' function which does not properly handle 'CBF_SMBITMAP objects' in a 'ViewHostMsg_ClipboardWriteObjectsAsync' message which lead to illegal memory accesses and arbitrary execution related to 'Type Confusion' issue.
- Error in 'rendering/FixedTableLayout.cpp' which leads to denial of service - 'Cross-origin bypass' in DOM methods.
- Error in 'page/EventHandler.cpp' causes Cross-origin keystroke redirection.
Affected
Google Chrome version prior to 5.0.375.70 on Linux
References
- http://code.google.com/p/chromium/issues/detail?id=43304
- http://code.google.com/p/chromium/issues/detail?id=43307
- http://code.google.com/p/chromium/issues/detail?id=43315
- http://code.google.com/p/chromium/issues/detail?id=43902
- http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html
- http://secunia.com/advisories/40072
Updated on 2015-03-25
Severity
Classification
-
CVE CVE-2010-1772, CVE-2010-1773, CVE-2010-2295, CVE-2010-2296, CVE-2010-2297, CVE-2010-2298, CVE-2010-2299, CVE-2010-2300, CVE-2010-2301, CVE-2010-2302 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Acrobat Multiple Unspecified Vulnerabilities-01 Sep13 (Windows)
- Adobe Acrobat Multiple Vulnerabilities - Windows
- Adobe Flash Player Buffer Overflow Vulnerability - Apr14 (Linux)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 Feb13 (Mac OS X)
- Adobe Acrobat and Reader PDF Handling Multiple Vulnerabilities (Linux)