Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2014.0140 Stable Google Chrome update addresses multiple vulnerabilities 10 December 2014 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Google Chrome Operating System: Windows Linux variants OS X Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Denial of Service -- Remote with User Interaction Access Confidential Data -- Remote with User Interaction Reduced Security -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2014-9164 CVE-2014-9163 CVE-2014-9162 CVE-2014-8443 CVE-2014-0587 CVE-2014-0580 Member content until: Friday, January 9 2015 Reference: ESB-2014.2338 OVERVIEW Google has released Chrome 39.0.2171.95 which includes an update for Adobe Flash as well as other fixes. [1] IMPACT Google references the Adobe Security bulletin, which provides the following details regarding the vulnerabilities: "Adobe has released security updates for Adobe Flash Player for Windows, Macintosh and Linux. These updates address vulnerabilities that could potentially allow an attacker to take control of the affected system." [2] MITIGATION The vendor recommends updating to the latest version of Google Chrome to correct these issues. REFERENCES [1] Stable Channel Update http://googlechromereleases.blogspot.com.au/2014/12/stable-channel-update.html [2] Security updates available for Adobe Flash Player http://helpx.adobe.com/security/products/flash-player/apsb14-27.html AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBVIfhiRLndAQH1ShLAQJMVw/+PCcBWv/kxOFfRQlb6EQ2sPoPXILLyGal fKx12W7xR312apx+FkKY4ZzgyM8Ambsz5aNCc0c1liiOZGOuKorRpqM4aYOYVYtg dBNFT3JDiIz4rXofPdza/KRo7FiBkNX40uIfrFI7WJ8ZogmcI0U44nmqrwe9157j t7Bf35BMze//y2xDzcc8/kHyg/kuxMWEXhCUQGfbX6mIYaTlKzkf2aC6Pf72NQZw AHURx6Ute9Xf7vJ15qJi2QhMgzYZBomWQXCNbPlvnbeC1xGEeG3JDKWsprGUoP66 RF/uimnpy2a49gU9Fwy0ZD4wK+C/UpCPo/HBnULqbcysWmharDyE3dxnc2qKtHdW RxR7804GeTOvTN0PMFogN4efBuxwZigxMS9RPrNAigQ3ky3p77V0/0Kt0LRtmMmZ CHSDS+mgFf38dp9dtDWuU2sVufyUCSVfu9MaLBAnH1afcJeedVLss82o/dFgmi/d ldIXcBU0r5hymzl0CRjKbxcct0wK495c5xx9SIRRb4hELJwXn8D5KMN9BB8amRdQ vdl7B2ce/voBboL9CgCOhF84Fa8YB3vmC167AKH7jkEVIY2sVbJOdjINb+TG4qVE UTTFyv3gfU02xY1AW/WYSD446X/LyRyB171SWpKivIBIRNYEnrJDYAj1DyxiAPsZ tC558hD3MdI= =3LY8 -----END PGP SIGNATURE-----