[Winvulns-announcements] BES Auto Notification: New Fixlets Published in Fixlet Site: 'Vulnerabilities to Windows Systems'

Notification of New Vulnerabilties to Windows Systems Fixlet Messages winvulns-announcements at bigmail.bigfix.com
Wed Sep 12 05:25:10 PDT 2012


Fixlet Site - 'Vulnerabilities to Windows Systems'
Current Version: 318	Published: Tue, 11 Sep 2012 20:44:46  GMT

New Fixlets:
============

***************************************************************
Title: Google Chrome before 21.0.1180.89 does not properly perform line breaking
Severity: Medium
Fixlet ID: 1486601
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval14866.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2865
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

***************************************************************
Title: The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (application crash) via unspecified vectors
Severity: Medium
Fixlet ID: 1513001
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15130.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2867
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: The SPDY implementation in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

***************************************************************
Title: Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in elements
Severity: High
Fixlet ID: 1560901
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15609.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2866
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: Google Chrome before 21.0.1180.89 does not properly perform a cast of an unspecified variable during handling of run-in elements, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

***************************************************************
Title: The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x through 1.6.10 and 1.8.x through 1.8.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a small value for a certain length field in a
Severity: Medium
Fixlet ID: 1564601
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15646.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-3548
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: The dissect_drda function in epan/dissectors/packet-drda.c in Wireshark 1.6.x through 1.6.10 and 1.8.x through 1.8.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a small value for a certain length field in a capture file.

***************************************************************
Title: Google Chrome before 21.0.1180.89 does not properly load URLs
Severity: High
Fixlet ID: 1571001
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15710.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2869
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: Google Chrome before 21.0.1180.89 does not properly load URLs, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a "stale buffer."

***************************************************************
Title: Race condition in Google Chrome before 21.0.1180.89 via vectors involving improper interaction between worker processes and an XMLHttpRequest (aka XHR) object
Severity: Medium
Fixlet ID: 1584201
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15842.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2868
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: Race condition in Google Chrome before 21.0.1180.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving improper interaction between worker processes and an XMLHttpRequest (aka XHR) object.

***************************************************************
Title: Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89
Severity: Medium
Fixlet ID: 1585301
Fixlet Link: http://oval.mitre.org/oval/definitions/data/oval15853.html
Fixlet Link: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-2872
Fixlet Link: http://nvd.nist.gov/cvss.cfm?vectorinfo

Fixlet Description: Cross-site scripting (XSS) vulnerability in an SSL interstitial page in Google Chrome before 21.0.1180.89 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.



More information about the WinVulns-Announcements mailing list