Google Chrome < 51.0.2704.63 Multiple Vulnerabilities (Mac OS X)

This script is Copyright (C) 2016-2017 Tenable Network Security, Inc.


Synopsis :

A web browser installed on the remote Mac OS X host is affected by
multiple vulnerabilities.

Description :

The version of Google Chrome installed on the remote Mac OS X host is
prior to 51.0.2704.63. It is, therefore, affected by multiple
vulnerabilities :

- Multiple unspecified flaws exist in extension bindings
that allow a remote attacker to bypass the same-origin
policy. No other details are available. (CVE-2016-1672,
CVE-2016-1676)

- Multiple unspecified flaws exist in Blink that allow a
remote attacker to bypass the same-origin policy. No
other details are available. (CVE-2016-1673,
CVE-2016-1675)

- An unspecified flaw exists in Extensions that allows a
remote attacker to bypass the same-origin policy.
No other details are available. (CVE-2016-1674)

- An unspecified type confusion error exists in V8
decodeURI that allows a remote attacker to disclose
potentially sensitive information. (CVE-2016-1677)

- A heap buffer overflow condition exists in V8 due to
improper validation of user-supplied input. A remote
attacker can exploit this to cause a denial of service
condition or the execution of arbitrary code.
(CVE-2016-1678)

- A heap use-after-free error exists in V8 bindings that
allows a remote attacker to deference already freed
memory and execute arbitrary code. (CVE-2016-1679)

- A heap use-after-free error exists in Google Skia that
allows a remote attacker to deference already freed
memory and execute arbitrary code. (CVE-2016-1680)

- A buffer overflow condition exists in OpenJPEG in the
opj_j2k_read_SPCod_SPCoc() function within file j2k.c
due to improper validation of user-supplied input. A
remote attacker can exploit this to cause a denial of
service condition or the execution of arbitrary code.
(CVE-2016-1681)

- An unspecified flaw exists in ServiceWorker that allows
a remote attacker to bypass the Content Security Policy
(CSP). No other details are available. (CVE-2016-1682)

- An unspecified out-of-bounds access error exists in
libxslt that allows a remote attacker to have an
unspecified impact. (CVE-2016-1683)

- An integer overflow condition exists in libxslt that
allows a remote attacker to have an unspecified impact.
(CVE-2016-1684)

- Multiple out-of-bounds read errors exist in PDFium that
allow a remote attacker to cause a denial of service
condition or disclose potentially sensitive information.
(CVE-2016-1685, CVE-2016-1686)

- An unspecified flaw exists in Extensions that allows a
remote attacker to disclose potentially sensitive
information. No other details are available.
(CVE-2016-1687)

- An out-of-bounds read error exists in V8 that allows a
remote attacker to cause a denial of service condition
or disclose potentially sensitive information.
(CVE-2016-1688)

- A heap buffer overflow condition exists in Media due to
improper validation of user-supplied input. A remote
attacker can exploit this to execute arbitrary code.
(CVE-2016-1689)

- A heap use-after-free error exists in Autofill that
allows a remote attacker to execute arbitrary code.
(CVE-2016-1690)

- A heap buffer overflow condition exists in Google Skia
due to improper validation of user-supplied input. A
remote attacker can exploit this to cause a denial of
service condition or the execution of arbitrary code.
(CVE-2016-1691)

- An unspecified flaw exists in ServiceWorker that allows
a remote attacker to carry out a limited bypass of the
same-origin policy. No other details are available.
(CVE-2016-1692)

- A flaw exists due to the Software Removal Tool being
downloaded over an HTTP connection. A man-in-the-middle
attacker can exploit this to manipulate its contents.
(CVE-2016-1693)

- A unspecified flaw exists that is triggered when HTTP
Public Key Pinning (HPKP) pins are removed when clearing
the cache. No other details are available.
(CVE-2016-1694)

- Multiple unspecified issues exist that allow a remote
attacker to execute arbitrary code. (CVE-2016-1695)

- A use-after-free error exists in 'MailboxManagerImpl'
that is triggered when handling GPU commands. A remote
attacker can exploit this to dereference already freed
memory, resulting in the execution of arbitrary code.
(VulnDB 140064)

See also :

http://www.nessus.org/u?e4d6f0fa

Solution :

Upgrade to Google Chrome version 51.0.2704.63 or later.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.0
(CVSS2#E:POC/RL:U/RC:UR)
Public Exploit Available : true