Buffer overflow in Google Chrome - CVE-2011-3106

 

Buffer overflow in Google Chrome - CVE-2011-3106

Published: May 24, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44042
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3106
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The WebSockets implementation in Google Chrome before 19.0.1084.52 does not properly handle use of SSL, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.


Affected software

Google Chrome

How to mitigate CVE-2011-3106

Install update from vendor's website.


External References

Related Security Bulletins