Buffer overflow in Google Chrome - CVE-2011-3106
Published: May 24, 2012 / Updated: August 11, 2020
Google Chrome
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The WebSockets implementation in Google Chrome before 19.0.1084.52 does not properly handle use of SSL, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
How to mitigate CVE-2011-3106
Sources
- http://code.google.com/p/chromium/issues/detail?id=122654
- http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.html
- http://osvdb.org/82251
- http://secunia.com/advisories/49277
- http://secunia.com/advisories/49306
- http://security.gentoo.org/glsa/glsa-201205-04.xml
- http://www.securityfocus.com/bid/53679
- http://www.securitytracker.com/id?1027098
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15470