漏洞信息详情
谷歌 Google Chrome 缓冲区错误漏洞
漏洞简介
Google Chrome是美国谷歌(Google)公司的一款Web浏览器。
Google Chrome 89.0.4389.114之前版本存在缓冲区错误漏洞,该漏洞源于Chrome浏览器IPC的越位读取,该漏洞允许远程攻击者破坏渲染进程,通过精心制作的HTML页面执行沙盒逃脱。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_30.html
参考网址
来源:GENTOO
链接:https://security.gentoo.org/glsa/202104-08
来源:MISC
链接:https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_30.html
来源:MISC
链接:https://crbug.com/1184399
来源:MISC
链接:https://packetstormsecurity.com/files/162973/Chrome-Legacy-ipc-Message-Passed-Via-Shared-Memory.html
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/EAJ42L4JFPBJATCZ7MOZQTUDGV4OEHHG/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/U3GZ42MYPGD35V652ZPVPYYS7A7LVXVY/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/VUZBGKGVZADNA3I24NVG7HAYYUTOSN5A/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162973/Chrome-Legacy-ipc-Message-Passed-Via-Shared-Memory.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1158
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021050103
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Chrome-multiple-vulnerabilities-34986
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1107
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-21198
受影响实体
暂无
补丁
- Google Chrome 安全漏洞的修复措施<!--2021-3-31-->
还没有评论,来说两句吧...