City
Epaper

CERT-In warns users of multiple bugs in Google Chrome, Zoho software

By IANS | Updated: July 7, 2022 15:05 IST

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has ...

Open in App

New Delhi, July 7 The Indian Computer Emergency Response Team (CERT-In), which comes under the IT Ministry, has warned users of multiple vulnerabilities in Google Chrome which could allow a remote attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system.

A remote attacker could exploit these vulnerabilities by sending specially crafted requests on the targeted system.

"Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code and denial-of-service (DoS) conditions on the targeted system," said CERT-In the advisory late on Wednesday.

These vulnerabilities exist in Google Chrome due to 'Heap Buffer' overflow in 'WebRTC', 'Type Confusion in V8' and 'Use after Free' in Chrome OS Shell.

The vulnerability (CVE-2022-2294) is being exploited in the wild, said the cyber agency, adding that the users are advised to apply patches urgently.

CERT-In also advised users against a 'Remote Code Execution' vulnerability that has been reported in a Zoho Corporation software which could be exploited by an unauthenticated remote attacker to execute arbitrary code on the targeted system.

This vulnerability exists in 'Zoho ManageEngine ADAudit Plus' due to a 'misconfigured XML' parser that processes user-supplied input without sufficient validation.

"Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on the targeted system," warned the cyber agency, advising the users to upgrade to the latest Zoho 'ManageEngine ADAudit Plus' security build update.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Secure ShellgoogleWord on macWho dgMicrosoft incUs google & youtubeSk duaDan patelBacPrivate institutesStory of reality tv
Open in App

Related Stories

Technology'In Memory of Victims': What Does the Black Ribbon Below Google Search Bar Mean?

Social ViralToday’s Google Googly: Where Did the Arabic Numerals Originate? Find the Correct Answer Here

TechnologyWhy Is Google Lens Coming to YouTube Shorts and What Can It Do?

EntertainmentGoogle and Kamal Haasan’s RKFI Join Forces to Launch an Interactive Search Animation for Thug Life

CricketToday’s Google Googly: What Is a Diamond Duck? Find the Correct Answer Here

International Realted Stories

InternationalUS Fed to wait for meaningful signs of weakness before rate cut: Experts

InternationalSpaceX Starship 36 Explodes During Static Fire Test (Watch Video)

InternationalPM Modi gifts silver candlestand to Croatian counterpart Plenkovic, Pattachitra painting to President Milanovic

International"Gen Asim Munir can not be trusted", says former US Envoy Zalmay Khalilzad

InternationalBilingual website dedicated to 14th Dalai Lama's 90th b'day celebration innagurated