CVE-2012-2849: Medium severity Google Chrome vulnerability
Off-by-one error in the GIF decoder in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2849?
CVE-2012-2849 has been classified as a denial of service vulnerability due to an off-by-one error in the GIF decoder of Google Chrome.
How do I fix CVE-2012-2849?
To fix CVE-2012-2849, update Google Chrome to version 21.0.1180.57 or later.
Who is affected by CVE-2012-2849?
Users of Google Chrome versions prior to 21.0.1180.57 on Mac OS X and Linux, and versions before 21.0.1180.60 on Windows are affected by CVE-2012-2849.
What causes CVE-2012-2849?
CVE-2012-2849 is caused by an off-by-one error in the GIF decoder which allows remote attackers to perform an out-of-bounds read.
What should I do if I cannot update for CVE-2012-2849?
If unable to update, consider using alternative browsers or mitigating risk by avoiding untrusted images.