Google Chrome < 62.0.3202.75 Multiple Vulnerabilities

high Nessus Network Monitor Plugin ID 700347

Synopsis

The remote host is utilizing a web browser that is affected by multiple attack vectors.

Description

The version of Google Chrome installed on the remote host is prior to 62.0.3202.75, and is affected by multiple vulnerabilities :

- An overflow condition exists in the 'NumberingSystem::createInstance()' function in 'i18n/numsys.cpp' that is triggered when handling locale strings with an overly long 'numbers' keyword value. This may allow a context-dependent attacker to cause a buffer overflow and potentially execute arbitrary code. (CVE-2017-15406)
- An overflow condition exists that is triggered when handling keyword values, which are not NUL-terminated. This may allow a context-dependent attacker to cause a buffer overflow and potentially execute arbitrary code. (CVE-2017-15396)

Solution

Upgrade to Chrome version 62.0.3202.75 or later.

See Also

https://chromereleases.googleblog.com/2017/10/stable-channel-update-for-desktop_26.html

Plugin Details

Severity: High

ID: 700347

Family: Web Clients

Published: 8/23/2018

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Patch Publication Date: 9/27/2018

Vulnerability Publication Date: 9/27/2017

Reference Information

CVE: CVE-2017-15396

BID: 101597