Release date: 2011-10-07
Updated on: 2011-10-07
Affected Systems:
Google Chrome <14.0.835.202
Description:
--------------------------------------------------------------------------------
Google Chrome is a Web browser developed by Google using the WebKit design engine.
Google Chrome has a security vulnerability. Remote attackers can exploit this vulnerability to control the affected system through a specially crafted webpage.
This vulnerability is caused by discarded pointer processing in the WebKit engine when Ruby labels and Their subtags are deleted in a specific order.
<* Source: Vupen
Link: http://seclists.org/bugtraq/2011/Oct/34
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.vupen.com/english/services/ba-index.php
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.google.com