Korean
<< Back
VID 28849
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Google Chrome which is older than 15.0.874.102 has been installed on the host. Google Chrome is a web browser released by Google. Google Chrome versions prior to 15.0.874.102 are vulnerable to multiple vulnerabilities.

- Several URL bar spoofing errors exist related to history handling and drag-and-drop of URLs. (CVE-2011-2845, CVE-2011-3875)
- Whitespace is stripped from the end of download filenames. (CVE-2011-3876)
- A cross-site scripting issue exists related to the 'appcache' internals page. (CVE-2011-3877)
- A race condition exists related to working process initialization. (CVE-2011-3878)
- An error exists related to redirection to 'chrome scheme' URIs. (CVE-2011-3879)
- Unspecified special characters may be used as delimiters in HTTP headers. (CVE-2011-3880)
- Several cross-origin policy violation issues exist. (CVE-2011-3881)
- Several use-after-free errors exist related to media buffer handling, counter handling, stale styles, plugins and editing, and video source handling. (CVE-2011-3882, CVE-2011-3883, CVE-2011-3885, CVE-2011-3888, CVE-2011-3890)
- Timing issues exist related to DOM traversal. (CVE-2011-3884)
- An out-of-bounds write error exists in the V8 JavaScript engine. (CVE-2011-3886)
- Cookie theft is possible via JavaScript URIs. (CVE-2011-3887)
- A heap overflow issue exists related to Web Audio. (CVE-2011-3889)
- Functions internal to the V8 JavaScript engine are exposed. (CVE-2011-3891)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://googlechromereleases.blogspot.com/2011/10/chrome-stable-release.html

* Platforms Affected:
Google Chrome versions prior to 15.0.874.102
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (15.0.874.102 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2011-2845,CVE-2011-3875,CVE-2011-3876,CVE-2011-3877,CVE-2011-3878,CVE-2011-3879,CVE-2011-3880,CVE-2011-3881,CVE-2011-3882 (CVE)
Related URL 50360 (SecurityFocus)
Related URL (ISS)