Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2016.0027 Multiple vulnerabilities have been identified in Google Chrome 10 March 2016 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Google Chrome Operating System: Linux variants OS X Windows Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction Denial of Service -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2016-1645 CVE-2016-1644 CVE-2016-1643 Member content until: Saturday, April 9 2016 OVERVIEW Multiple vulnerabilities have been identified in Google Chrome prior to version 49.0.2623.87. [1] IMPACT The vendor has provided the following details regarding this issue: "This update includes 3 security fixes that were contributed by external researchers. Please see the Chromium security page for more information. [$5000][589838] High CVE-2016-1643: Type confusion in Blink. Credit to cloudfuzzer. [$3500][590620] High CVE-2016-1644: Use-after-free in Blink. Credit to Atte Kettunen of OUSPG. [587227] High CVE-2016-1645: Out-of-bounds write in PDFium. Credit to anonymous working with HP's Zero Day Initiative" [1] MITIGATION The vendor recommends updating to the latest version of Google Chrome to correct these issues. [1] REFERENCES [1] Stable Channel Update http://googlechromereleases.blogspot.com.au/2016/03/stable-channel-update_8.html AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBVuDPvX6ZAP0PgtI9AQJF/Q//ZZFg6Q0LjdLDhVzTQrFsb6HwHZCmPWBJ zzoYQ35zj4I8e13NGEGTumxEynrwSrir849n7bIvrXjSJBBRcvDfhRsLfEc2Dacz 1746xWmdZCwV4o7ndDfWnIC2O4aZ1ty9u720+apc79NM3apEBFyvkdT+4D7VSdS7 Ht0ROg+Gc62I1vsue1EIzRAOIJacdIcKajIRwRa8XK5k8QenAYOo+Y+RX2e64DAb eRmiIpHQ97PRvmBKm3mgPG1Rm7mAZ7+AkYiNDpkjbtcO+0ODd6nT153dDP7Qql0r oTpWalH5cnlxxmq8m3pmkWtbwhJNiyKiY9SpLjOKi2xpLI5gRtDnja9CmxPU5Vrw sM//N8hh49QBTiWNAEZHOmHip3tNYHyXWLaizjmPn/qlaO6Zh+NcyKK11PS1BPYD FNzsLKQq+RfNtz+pVL3+4JsMnJ0K6YDNOok0Xs+71vxpIZFa/nKN5n8yF2bY2GLo r//ZEbIBx+nSXKxWdGgpXViQMX9aY6goma5yfpMl5jBx6PyIIPRq8SqY3HR+zGNz aksqE/3IFGWmwqbfhhVQzOOWMKv7WiDGq7iWgX/4xcSbT0bJjhFN2gYr8YF292lA XVIJXZXGOPeLAt+obhg13EllBmilTQr8Gv4NfZ0Ti7vlhK24gufaT1Z2VLALPPeb GRL+2F7BDaE= =FhCi -----END PGP SIGNATURE-----