Published:2010/11/26  Last Updated:2010/11/26

JVN#36765384
Google Chrome information disclosure vulnerability

Overview

Google Chrome contains an information disclosure vulnerability.

Products Affected

  • Google Chrome prior to 3.0

Description

Google Chrome contains an information disclosure vulnerability caused by the improper handling of XML files.

Impact

When viewing a specially crafted web page, information may be disclosed.

Solution

Update the Software
Update to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Google Google Chrome

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Takayoshi Isayama from Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2010-3917
JVN iPedia JVNDB-2010-000056