Contributed by: Lauren Gerber
Date: June 12, 2009
|
|
Google Chrome Webkit Vulnerabilities |
|
|
I welcome you to yet another fun and exciting update on computer security vulnerabilities. The vulnerabilities I will be talking about today relate to Google Chrome. I'm here to bring your attention to two vulnerabilities that were reported. These vulnerabilities run the risk of a system being exploited by malicious individuals in order to compromise users systems and possibly gain access to confidential information.
The Two Vulnerabilities Found In Google Chrome:
- There is an error that exists in the WebKit when the handling of specific drag events takes place. This runs the risk of being exploited by malicious individuals in order to access confidential information. This only occurs when particular content is being dragged over a malicious web page.
- This vulnerability takes place when JavaScript Code is executed to set a particular property of an HTML tag, resulting in child elements of the tag being freed. An error can then be encountered in the remaining HTML and the freed tag values can be referenced, and thus exploited by attackers to control values used as function pointers.
There are quite a few risks related to these vulnerabilities, with the inclusion of the possible execution of arbitrary code. 
Google Chrome as we all know is a fairly new web browser, which is continuously growing in popularity. One of the files which pertain to Google Chrome includes: chrome.exe.
Google desktop also seems to be growing in its popularity; it is desktop search software which has been created by Google. This software has some remarkable features as well as some wonderful Google Gadgets. Some of the files which relate to Google desktop may include but are not limited to the following: googledesktopresources_es.dl..., a0002240.dll, googledesktopsetuphelper.exe, a0002238.dll, a0002231.exe as well as a0002242.dll.
The question that one may ask is what versions are affected by these vulnerabilities? The versions of Google Chrome that have been affected are a version prior to 2.0.172.31. Therefore the solution to this vulnerability relates to updating to version 2.0.172.31.
User Comments