Affected Versions:
Google Chrome 5.0
Vulnerability description:
Bugtraq id: 41334CVE ID: CVE-2010-2645, CVE-2010-2646, CVE-2010-2647, CVE-2010-2648,
CVE-2010-2649, CVE-2010-2650, CVE-2010-2651, CVE-2010-2652Google Chrome is Google's open source WEB browser. Chrome 5.0.375.99 fixes multiple security vulnerabilities,
A user who is cheated to access a malicious webpage may cause denial of service or completely intrude into the user system. 1) when using WebGL, Chrome may encounter an out-of-bounds read access error. 2) Chrome does not properly isolate the IFRAME element in the sandbox. 3) invalid SVG documents may cause memory corruption. 4) errors in Unicode bidirectional Algorithm Implementation in Chrome may cause memory corruption. 5) The Chrome CSS implementation does not properly render the style, which may trigger memory corruption. 6) Chrome does not properly implement the modal dialog box, which may cause DOS.
<* Reference
Sergey glaz.pdf
SkyLined
Wushi (
Wooshi@gmail.com)
Link:
Http://secunia.com/advisories/40479/
Http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.html
*>Security suggestions:
Vendor patch: Google ------ the current vendor has released the upgrade patch to fix this security problem, please go to the vendor's home page download: http://www.google.com