First published: Thu Mar 22 2012(Updated: )
Google Chrome before 17.0.963.83 allows remote attackers to bypass the Same Origin Policy via vectors involving a "magic iframe."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <17.0.963.83 | |
openSUSE | =12.1 | |
iPhone OS | <5.1.1 | |
Safari | <5.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3056 has a medium severity rating due to its potential for allowing remote attackers to bypass security mechanisms.
To fix CVE-2011-3056, update Google Chrome to version 17.0.963.83 or later.
CVE-2011-3056 affects Google Chrome versions prior to 17.0.963.83.
Yes, CVE-2011-3056 can also affect Apple Safari versions prior to 5.1.7 and Apple iPhone OS versions prior to 5.1.1.
CVE-2011-3056 facilitates attacks that allow for the bypassing of the Same Origin Policy through a technique involving a 'magic iframe'.