Buffer overflow in Google Chrome - CVE-2011-3106
Published: May 24, 2012 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The WebSockets implementation in Google Chrome before 19.0.1084.52 does not properly handle use of SSL, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
Affected software
How to mitigate CVE-2011-3106
External References
- http://code.google.com/p/chromium/issues/detail?id=122654
- http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.html
- http://osvdb.org/82251
- http://secunia.com/advisories/49277
- http://secunia.com/advisories/49306
- http://security.gentoo.org/glsa/glsa-201205-04.xml
- http://www.securityfocus.com/bid/53679
- http://www.securitytracker.com/id?1027098
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15470