CVE-2012-2847: Medium severity Google Chrome vulnerability
Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not request user confirmation before continuing a large series of downloads, which allows user-assisted remote attackers to cause a denial of service (resource consumption) via a crafted web site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2847?
The severity of CVE-2012-2847 is considered medium as it may lead to resource exhaustion.
How do I fix CVE-2012-2847?
To fix CVE-2012-2847, upgrade Google Chrome to a version later than 21.0.1180.57.
What versions of Google Chrome are affected by CVE-2012-2847?
CVE-2012-2847 affects Google Chrome versions before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows.
What type of attack does CVE-2012-2847 facilitate?
CVE-2012-2847 facilitates a denial of service attack through uncontrolled downloading.
Is user confirmation required for downloads in vulnerable versions of Chrome under CVE-2012-2847?
No, vulnerable versions of Chrome do not request user confirmation before proceeding with a large series of downloads.