VID |
28864 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
A version of Google Chrome which is older than 23.0.1271.97 has been installed on the host. Google Chrome is a web browser released by Google. Google Chrome versions prior to 23.0.1271.97 are vulnerable to multiple vulnerabilities.
- Use-after-free errors exist related to visibility events and the URL loader. (CVE-2012-5139, CVE-2012-5140) - An unspecified error exists related to instantiation of the 'Chromoting' client plugin. (CVE-2012-5141) - An unspecified error exists related to history navigation that can lead to application crashes. (CVE-2012-5142) - An integer overflow error exists related to the 'PPAPI' image buffers. (CVE-2012-5143) - A stack corruption error exists related to 'AAC' decoding. (CVE-2012-5144) - The bundled version of Adobe Flash Player contains flaws that can lead to arbitrary code execution. (CVE-2012-5676, CVE-2012-5677, CVE-2012-5678)
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://googlechromereleases.blogspot.kr/2012/12/stable-channel-update.html
* Platforms Affected: Google Chrome versions prior to 23.0.1271.97 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version Google Chrome (23.0.1271.97 or later), available from the Google Web site at http://www.google.com/chrome/ |
Related URL |
CVE-2012-5139,CVE-2012-5140,CVE-2012-5141,CVE-2012-5142,CVE-2012-5143,CVE-2012-5144,CVE-2012-5676,CVE-2012-5677 (CVE) |
Related URL |
56892,56896,56898,56903 (SecurityFocus) |
Related URL |
(ISS) |
|