[Japanese]

JVNDB-2010-000056

Google Chrome information disclosure vulnerability

Overview

Google Chrome contains an information disclosure vulnerability.

Google Chrome contains an information disclosure vulnerability caused by the improper handling of XML files.

Takayoshi Isayama from Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V2 Severity:
Base Metrics 4.3 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


Google
  • Google Chrome prior to 3.0

Impact

When viewing a specially crafted web page, information may be disclosed.
Solution

[Update the Software]
Update to the latest version according to the information provided by the developer.
Vendor Information

Google
CWE (What is CWE?)

  1. Information Exposure(CWE-200) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2010-3917
References

  1. JVN : JVN#36765384
  2. National Vulnerability Database (NVD) : CVE-2010-3917
Revision History

  • [2010/11/26]
      Web page published