SB2011120703 - Multiple vulnerabilities in Techland Chrome
Published: December 7, 2011 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2010-5069)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The Cascading Style Sheets (CSS) implementation in Google Chrome 4 does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document. NOTE: this may overlap CVE-2010-2264.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2010-5073)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.
Remediation
Install update from vendor's website.