CVE-2011-3046
CVE-2011-3046
The extension subsystem in Google Chrome before 17.0.963.78 does not properly handle history navigation, which allows remote attackers to execute arbitrary code by leveraging a "Universal XSS (UXSS)" issue.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://code.google.com/p/chromium/issues/detail?id=117226http://code.google.com/p/chromium/issues/detail?id=117230http://googlechromereleases.blogspot.com/2012/03/chrome-stable-channel-update.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-03/msg00012.htmlhttp://secunia.com/advisories/47292http://secunia.com/advisories/48321http://secunia.com/advisories/48419http://secunia.com/advisories/48527http://security.gentoo.org/glsa/glsa-201203-19.xmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14686