Korean
<< Back
VID 28873
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description A version of Google Chrome which is older than 28.0.1500.71 has been installed on the host. Google Chrome is a web browser released by Google. Google Chrome versions prior to 28.0.1500.71 are vulnerable to multiple vulnerabilities.

- A vulnerability exists that exposes HTTP in SSL to a man-in-the-middle attack. (CVE-2013-2853)
- Block pop-unders in various scenarios. (CVE-2013-2867)
- An error exists related to an incorrect sync of the NPAPI extension component. (CVE-2013-2868)
- An unspecified flaw exists due to a lack of entropy in renderers. (CVE-2013-2872)
- Use-after-free errors exist related to network sockets, input handling, and resource loading. (CVE-2013-2870, CVE-2013-2871, CVE-2013-2873)
- A screen data leak error exists related to GL textures. (CVE-2013-2874)
- An extension permission error exists related to interstitials. (CVE-2013-2876)
- Multiple out-of-bounds errors exist related to JPEG2000, SVG, text handling and XML parsing. (CVE-2013-2869, CVE-2013-2875, CVE-2013-2877, CVE-2013-2878)
- An unspecified error exists when setting up sign-in and sync. (CVE-2013-2879)
- The vendor reports various, unspecified errors exist. (CVE-2013-2880)

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
http://googlechromereleases.blogspot.kr/2013/07/stable-channel-update.html

* Platforms Affected:
Google Chrome versions prior to 28.0.1500.71
Microsoft Windows Any version
Recommendation Upgrade to the latest version Google Chrome (28.0.1500.71 or later), available from the Google Web site at http://www.google.com/chrome/
Related URL CVE-2013-2853,CVE-2013-2867,CVE-2013-2868,CVE-2013-2869,CVE-2013-2870,CVE-2013-2871,CVE-2013-2872,CVE-2013-2873,CVE-2013-2874,CVE-2013-2875 (CVE)
Related URL 61046,61047,61049,61050,61051,61052,61053,61054,61055,61056,61057,61058,61059,61060,61061 (SecurityFocus)
Related URL (ISS)