Release date:
Updated on:
Affected Systems:
Google Chrome <33.0.1750.146
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65930
CVE (CAN) ID: CVE-2013-6663, CVE-2013-6664, CVE-2013-6665, CVE-2013-6666, CVE-2013-6667
Google Chrome is a Web browser tool developed by Google.
Chrome 33.0.1750.146 and earlier versions have multiple vulnerabilities. After successful exploitation, malicious users can bypass certain security restrictions and control user systems.
1. There is a reuse error when processing SVG images after release.
2. There is a reuse error in Speech Recognition after release.
3. Errors occur when processing software rendering, which can cause heap buffer overflow.
4. The voice does not properly limit the requests in the flash packet header request.
5. V8 vulnerabilities exist.
<* Source: Atte Kettunen
Halil Zhani
Cloudfuzzer
Netfuzzerr
Link: http://secunia.com/advisories/57194/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.google.com
Http://googlechromereleases.blogspot.com/2014/03/stable-channel-update.html
Chrome details: click here
Chrome: click here
Solution to Chrome dependency installation in Ubuntu 13.04
Install Chrome in openSUSE
Convenient certificate management function of Chrome browser in Ubuntu
Install Google Chrome in CentOS 6.x