Bird_banner_small4
Google Chrome and Apple Safari Runin Handling Use After Free
TSL ID TSL20120423-07
CVE ID(s) CVE-2011-3068
Severity High
Description

A code execution vulnerability exists Apple Safari and Google Chrome. The vulnerability is due to a use-after-free condition while handling run-in boxes.

A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to visit a malicious web site. This can lead to memory corruption and the possibility of code execution in the context of the affected user. If code execution is unsuccessful, the application may terminate abnormally.

Google has released an advisory and a new version of Chrome to address this vulnerability:

http://googlechromereleases.blogspot.ca/2012/04/stable-and-beta-channel-updates.html

A new version of Safari addressing this vulnerability is not yet available.

Affected Products
  • Apple Computer Safari 5.x prior to 5.1.4
  • Google Chrome prior to 18.0.1025.151
CVSS Score Base 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P):
  • Access vector is NETWORK
  • Access complexity is MEDIUM
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is PARTIAL
  • Impact of this vulnerability on data integrity is PARTIAL
  • Impact of this vulnerability on data availability is PARTIAL
Temporal 5.3 (E:POC/RL:OF/RC:C):
  • The exploitability level of this vulnerability is PROOF OF CONCEPT
  • The remediation level of this vulnerability is OFFICIAL FIX
  • The report confidence level of this vulnerability is CONFIRMED
Identifiers
OSVDB
References http://googlechromereleases.blogspot.ca/2012/04/stable-and-beta-channel-updates.html
http://trac.webkit.org/browser/trunk/LayoutTests/fast/runin/run-in-layer-not-removed-crash.html?rev=111263
Related Threats