[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Denial of service vulnerability in Google Chrome Frame plugin via an _blank value

ID: oval:org.secpod.oval:def:14263Date: (C)2013-07-09   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The host is installed with Google Chrome Frame plugin before 26.0.1410.28 and is prone to denial of service vulnerability. The flaw is present in the Hook_Terminate function in chrome_frame/protocol_sink_wrap.cc, which does not properly handle attach tab requests. Successful exploitation allows remote attackers to cause a denial of service via an _blank value for the target attribute of an A element.

Platform:
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Product:
Google Chrome Frame
Reference:
CVE-2013-2493
CVE    1
CVE-2013-2493

© SecPod Technologies