Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:CHROME:IFRAME-INFO-DIS

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Google Chrome iframe Information Disclosure

Release Date

2012/12/18

Update Number

2213

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Google Chrome iframe Information Disclosure


This signature detects attempts to exploit a known vulnerability against Google Chrome iframe. A successful attack can lead to unauthorized information disclosure.

Extended Description

Google Chrome is prone to multiple vulnerabilities: - multiple remote code-execution issues - multiple information-disclosure issues - a code-execution issue - a cross-origin information-disclosure issue Attackers can exploit these issues to obtain sensitive information, execute arbitrary code in the context of the browser, and carry out other attacks. Versions prior to Chrome 4.0.249.89 are vulnerable.

Affected Products

  • Google chrome 0.2.149.27
  • Google chrome 0.2.149.29
  • Google chrome 0.2.149.30
  • Google chrome 0.3.154 9
  • Google chrome 1.0.154.36
  • Google chrome 1.0.154.46
  • Google chrome 1.0.154.48
  • Google chrome 1.0.154.53
  • Google chrome 1.0.154.55
  • Google chrome 1.0.154.59
  • Google chrome 1.0.154.61
  • Google chrome 1.0.154.64
  • Google chrome 1.0.154.65
  • Google chrome 2.0.172.30
  • Google chrome 2.0.172.31
  • Google chrome 2.0.172.33
  • Google chrome 2.0.172.37
  • Google chrome 2.0.172.43
  • Google chrome 3.0.195.21
  • Google chrome 3.0.195.24
  • Google chrome 3.0.195.32
  • Google chrome 3.0.195.33
  • Google chrome 3.0 Beta
  • Google chrome 4.0.249.78
  • Ubuntu ubuntu_linux 10.04 Amd64
  • Ubuntu ubuntu_linux 10.04 I386
  • Ubuntu ubuntu_linux 10.04 Powerpc
  • Ubuntu ubuntu_linux 10.04 Sparc
  • Ubuntu ubuntu_linux 10.10 amd64
  • Ubuntu ubuntu_linux 10.10 i386
  • Ubuntu ubuntu_linux 10.10 powerpc
  • Ubuntu ubuntu_linux 9.10 Amd64
  • Ubuntu ubuntu_linux 9.10 I386
  • Ubuntu ubuntu_linux 9.10 Lpia
  • Ubuntu ubuntu_linux 9.10 Powerpc
  • Ubuntu ubuntu_linux 9.10 Sparc
  • Webkit_open_source_project webkit 1.2.2
  • Webkit_open_source_project webkit 1.2.2-1
  • Webkit_open_source_project webkit 1.2.3
  • Webkit_open_source_project webkit

References

  • BugTraq: 38177
  • CVE: CVE-2010-0556
  • CVE: CVE-2010-0315

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out