[Japanese]

JVNDB-2010-000056

Google Chrome information disclosure vulnerability

Overview

Google Chrome contains an information disclosure vulnerability.

Google Chrome contains an information disclosure vulnerability caused by the improper handling of XML files.

Takayoshi Isayama from Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None

Affected Products


Google
  • Google Chrome prior to 3.0

Impact

When viewing a specially crafted web page, information may be disclosed.
Solution

[Update the Software]
Update to the latest version according to the information provided by the developer.
Vendor Information

Google
CWE (What is CWE?)

  1. Information Exposure(CWE-200) [IPA Evaluation]
CVE (What is CVE?)

References

  1. JVN : JVN#36765384
Revision History

[2010/11/26]
  Web page published