VULNERABILITIES / FIXES - May 01, 2012

by Carol~ Moderator - 5/1/12 7:02 AM

Google Chrome Multiple Vulnerabilities

Release Date : 2012-05-01

Criticality level : Highly critical
Impact : System access
Unknown
Where : From remote
Solution Status : Vendor Patch

Software: Google Chrome 18.x

Description:
Multiple vulnerabilities have been reported in Google Chrome, where some have an unknown impact and others can be exploited by malicious people to compromise a user's system.

1) A use-after-free error exists in floats handling.

2) A use-after-free error exists within the xml parser.

3) An error exists within the IPC validation.

4) A race condition exists within the sandbox IPC.

5) A second use-after-free error exists in floats handling.

The vulnerabilities are reported in versions prior to 18.0.1025.168.

Solution:
Update to version 18.0.1025.168.

Provided and/or discovered by:
The vendor credits:
1) Marty Barbella, Google Chrome Security Team and miaubiz
2) SkyLined, Google Chrome Security Team and wushi, team509 via iDefense
3) PinkiePie
4) Willem Pinckaers, Matasano.
5) miaubiz

Original Advisory:
http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.html

http://secunia.com/advisories/48992/