SB2012100904 - Multiple vulnerabilities in Techland Chrome



SB2012100904 - Multiple vulnerabilities in Techland Chrome

Published: October 9, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012100904
Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 20% Medium 80%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 secuirty vulnerabilities.


1) Race condition (CVE-ID: CVE-2012-5108)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices.


2) Out-of-bounds read (CVE-ID: CVE-2012-5109)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression.


3) Out-of-bounds read (CVE-ID: CVE-2012-5110)

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.


4) Input validation error (CVE-ID: CVE-2012-5111)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors.


5) Input validation error (CVE-ID: CVE-2012-2900)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Skia, as used in Google Chrome before 22.0.1229.92, does not properly render text, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via unknown vectors.


Remediation

Install update from vendor's website.