Google Chrome < 10.0.648.205 Multiple Vulnerabilities

high Nessus Plugin ID 53392

Synopsis

The remote host contains a web browser that is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote host is earlier than 10.0.648.205. Such versions are affected by multiple vulnerabilities :

- An off-by-three issue exists in the GPU process.
(CVE-2011-1300)

- A use-after-free issue exists in the GPU process.
(CVE-2011-1301)

- A heap overflow issue exists in the GPU process.
(CVE-2011-1302)

Solution

Upgrade to Google Chrome 10.0.648.205 or later.

See Also

http://www.nessus.org/u?bde4912e

Plugin Details

Severity: High

ID: 53392

File Name: google_chrome_apsa11-02.nasl

Version: 1.15

Type: local

Agent: windows

Family: Windows

Published: 4/13/2011

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: SMB/Google_Chrome/Installed

Exploit Ease: No known exploits are available

Patch Publication Date: 4/14/2011

Vulnerability Publication Date: 4/11/2011

Reference Information

CVE: CVE-2011-1300, CVE-2011-1301, CVE-2011-1302

BID: 47377

SECUNIA: 44141