Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Google Chrome < 47.0.2526.106 Multiple Vulnerabilities

High

Synopsis

The remote host is utilizing a web browser that is affected by multiple vulnerabilities.

Description

The version of Google Chrome on the remote host is prior to 47.0.2526.106 and is affected by the following vulnerabilities :

- The 'WebCursor::Deserialize()' method in file 'common/cursors/webcursor.cc' is affected by an integer overflow condition that allows an attacker to execute arbitrary code. (CVE-2015-6792) - The 'MidiManagerAlsa::DispatchSendMidiData()' method in file 'media/midi/midi_manager_alsa.cc' contains an unspecified flaw that allows an attacker to execute arbitrary code outside of sandbox restrictions. (CVE-2015-8664)

In addition to these, the bundled Flash Player component in this version of Google Chrome may be affected by the following vulnerabilities :

- A type confusion error exists that a remote attacker can exploit to execute arbitrary code. (CVE-2015-8644) - An integer overflow condition exists that a remote attacker can exploit to execute arbitrary code. (CVE-2015-8651) - Multiple use-after-free errors exist that a remote attacker can exploit to execute arbitrary code. (CVE-2015-8634, CVE-2015-8635, CVE-2015-8638, CVE-2015-8639, CVE-2015-8640, CVE-2015-8641, CVE-2015-8642, CVE-2015-8643, CVE-2015-8646, CVE-2015-8647, CVE-2015-8648, CVE-2015-8649, CVE-2015-8650) - Multiple memory corruption issues exist that allow a remote attacker to execute arbitrary code. (CVE-2015-8459, CVE-2015-8460, CVE-2015-8636, CVE-2015-8645)

Solution

Update the Chrome browser to 47.0.2526.106 or later.