Korean
<< Back
VID 28864
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Google Chrome which is older than 23.0.1271.97 has been installed on the host. Google Chrome is a web browser released by Google. Google Chrome versions prior to 23.0.1271.97 are vulnerable to multiple vulnerabilities.

- Use-after-free errors exist related to visibility events and the URL loader. (CVE-2012-5139, CVE-2012-5140)
- An unspecified error exists related to instantiation of the 'Chromoting' client plugin. (CVE-2012-5141)
- An unspecified error exists related to history navigation that can lead to application crashes. (CVE-2012-5142)
- An integer overflow error exists related to the 'PPAPI' image buffers. (CVE-2012-5143)
- A stack corruption error exists related to 'AAC' decoding. (CVE-2012-5144)
- The bundled version of Adobe Flash Player contains flaws that can lead to arbitrary code execution. (CVE-2012-5676, CVE-2012-5677, CVE-2012-5678)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://googlechromereleases.blogspot.kr/2012/12/stable-channel-update.html

* Platforms Affected:
Google Chrome versions prior to 23.0.1271.97
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (23.0.1271.97 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2012-5139,CVE-2012-5140,CVE-2012-5141,CVE-2012-5142,CVE-2012-5143,CVE-2012-5144,CVE-2012-5676,CVE-2012-5677 (CVE)
Related URL 56892,56896,56898,56903 (SecurityFocus)
Related URL (ISS)