HomeBusinessCERT-In finds multiple bugs in Google Chrome OS, GitLab

CERT-In finds multiple bugs in Google Chrome OS, GitLab

New Delhi, July 2 (IANS) The Indian Computer Emergency Response Team (CERT-In), which comes under the Ministry of Electronics & Information Technology, has warned users of multiple vulnerabilities in Google Chrome OS and GitLab, which could allow an attacker to execute arbitrary code on the targeted system.

LTS channel for Google ChromeOS versions prior to 120.0.6099.315 is the affected software.

On the other hand, the affected software in GitLab include — GitLab Community Edition (CE) versions prior to 17.1.1, 17.0.3 and 16.11.5 and GitLab Enterprise Edition (EE) versions prior to 17.1.1, 17.0.3 and 16.11.5.

“Multiple vulnerabilities have been reported in LTS channel for ChromeOS which could be exploited by an attacker to execute arbitrary code on the targeted system,” said the CERT-In advisory.

As per the cyber agency, these vulnerabilities exist in Google Chrome OS due to Heap buffer overflow in WebRTC and Use after free in Media Session.

An attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted web page.

The vulnerabilities reported in GitLab exist in various components of GitLab community Edition (CE) and Enterprise Edition (EE).

Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, access sensitive information, cause cross-site scripting, bypass security restrictions and cause denial of service condition on the targeted system, according to the cyber agency.

CERT-In has suggested users apply appropriate security updates as recommended by the companies.

–IANS

shs/rad

Go to Source

Disclaimer

The information contained in this website is for general information purposes only. The information is provided by TodayIndia.news and while we endeavour to keep the information up to date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk.

In no event will we be liable for any loss or damage including without limitation, indirect or consequential loss or damage, or any loss or damage whatsoever arising from loss of data or profits arising out of, or in connection with, the use of this website.

Through this website you are able to link to other websites which are not under the control of TodayIndia.news We have no control over the nature, content and availability of those sites. The inclusion of any links does not necessarily imply a recommendation or endorse the views expressed within them.

Every effort is made to keep the website up and running smoothly. However, TodayIndia.news takes no responsibility for, and will not be liable for, the website being temporarily unavailable due to technical issues beyond our control.

For any legal details or query please visit original source link given with news or click on Go to Source.

Our translation service aims to offer the most accurate translation possible and we rarely experience any issues with news post. However, as the translation is carried out by third part tool there is a possibility for error to cause the occasional inaccuracy. We therefore require you to accept this disclaimer before confirming any translation news with us.

If you are not willing to accept this disclaimer then we recommend reading news post in its original language.

RELATED ARTICLES
- Advertisment -

Most Popular