Google Chrome < 62.0.3202.75 Multiple Vulnerabilities
High Nessus Network Monitor Plugin ID 700347
SynopsisThe remote host is utilizing a web browser that is affected by multiple attack vectors.
DescriptionThe version of Google Chrome installed on the remote host is prior to 62.0.3202.75, and is affected by multiple vulnerabilities :
- An overflow condition exists in the 'NumberingSystem::createInstance()' function in 'i18n/numsys.cpp' that is triggered when handling locale strings with an overly long 'numbers' keyword value. This may allow a context-dependent attacker to cause a buffer overflow and potentially execute arbitrary code. (CVE-2017-15406)
- An overflow condition exists that is triggered when handling keyword values, which are not NUL-terminated. This may allow a context-dependent attacker to cause a buffer overflow and potentially execute arbitrary code. (CVE-2017-15396)
SolutionUpgrade to Chrome version 62.0.3202.75 or later.