Use-after-free in Google Chrome - CVE-2011-1059

 

Use-after-free in Google Chrome - CVE-2011-1059

Published: February 22, 2011 / Updated: August 11, 2020


Vulnerability identifier: #VU45302
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2011-1059
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing vectors that entice a user to resubmit a form, related to improper handling of provisional items by the HistoryController component, aka rdar problem 8938557. A user-assisted remote attackers can cause a denial of service (application crash) or possibly have unspecified other impact.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Google Chrome

How to mitigate CVE-2011-1059

Update to version 11.0.672.2.

Google Chrome - update to 11.0.672.2

External References

Related Security Bulletins