Vulnerability Description
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | < 8.0.552.344 | |
| Chrome | < 8.0.552.237 |
Related Weaknesses (CWE)
References
- http://code.google.com/p/chromium/issues/detail?id=68666Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70468Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party AdvisoryVDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64676Third Party AdvisoryVDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=68666Permissions Required
- http://googlechromereleases.blogspot.com/2011/01/chrome-stable-release.htmlVendor Advisory
- http://osvdb.org/70468Broken Link
- http://secunia.com/advisories/42951Third Party Advisory
- http://www.securityfocus.com/bid/45788Third Party AdvisoryVDB Entry
- http://www.srware.net/forum/viewtopic.php?f=18&t=2054Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64676Third Party AdvisoryVDB Entry
FAQ
What is CVE-2011-0485?
CVE-2011-0485 is a vulnerability with a CVSS score of 10.0 (HIGH). Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "st...
How severe is CVE-2011-0485?
CVE-2011-0485 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0485?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome Os, Google Chrome.