Input validation error in Google Chrome - CVE-2011-3955

 

Input validation error in Google Chrome - CVE-2011-3955

Published: February 9, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44312
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-3955
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Google Chrome before 17.0.963.46 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors that trigger the aborting of an IndexedDB transaction.


Affected software

Google Chrome
Gentoo Linux

How to mitigate CVE-2011-3955

Install update from vendor's website.

Google Chrome - update to 17.0.963.46

External References

Related Security Bulletins