Vulnerability Name: | CVE-2009-3263 (CCN-53269) | ||||||||
Assigned: | 2009-09-15 | ||||||||
Published: | 2009-09-15 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content." Per http://www.securityfocus.com/archive/1/archive/1/506517/100/0/threaded VII. SOLUTION ------------------------- Chrome: Upgrade to latest version of Google Chrome (v3.0.195.21 or higher). If you remain connected to the internet, this should be automatic. Opera: Wait for upcoming patch for Scenario (3) in next minor release (non-alpha/beta) of Opera 10 [Opera 9 users need to upgrade]. However, you will still continue to be vulnerable to script execution. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CONFIRM Type: UNKNOWN http://code.google.com/p/chromium/issues/detail?id=21238 Source: MITRE Type: CNA CVE-2009-3263 Source: CCN Type: Google Chrome Releases Stable Channel Update Source: CONFIRM Type: Vendor Advisory http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.html Source: CCN Type: SA36770 Google Chrome Security Bypass and Cross-Site Scripting Source: SECUNIA Type: Vendor Advisory 36770 Source: CCN Type: SecureThoughts Web Site Exploiting Chrome and Operas inbuilt ATOM/RSS reader with Script Execution and more Source: MISC Type: Exploit http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/ Source: CCN Type: OSVDB ID: 58192 Google Chrome RSS / Atom Feed XSS Source: BUGTRAQ Type: UNKNOWN 20090916 Exploiting Chrome and Opera's inbuilt ATOM/RSS reader with Script Execution and more Source: BID Type: UNKNOWN 36416 Source: CCN Type: BID-36416 Google Chrome prior to 3.0.195.21 Multiple Security Vulnerabilities Source: XF Type: UNKNOWN googlechrome-rss-atom-xss(53269) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |