RULE(RULE ID:322202)

Rule General Information
Release Date: 2019-07-02
Rule Name: Google Chrome SVG Security Policy Bypass Vulnerability (CVE-2009-3931)
Severity:
CVE ID:
Rule Protection Details
Description: Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg files, which are automatically executed by Safari; (4) .xml files; (5) .htt files; (6) .xsl files; (7) .xslt files; and (8) image files that are forbidden by the victim's site policy.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:36947
http://code.google.com/p/chromium/issues/detail?id=23979
http://codereview.chromium.org/243115
http://codereview.chromium.org/261022
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://dl.google.com/tag/s/appguid%3D%7B8A69D345-D564-463C-AFF1-A69D9E530F96%7D%26iid%3D%7B346D5B77-E0DB-678C-842B-A3136A0B5D10%7D%26lang%3Dzh-CN%26browser%3D2%26usagestats%3D1%26appname%3D%25E8%25B0%25B7%25E6%25AD%258C%25E6%25B5%258F%25E8%25A7%2588%25E5%2599%25A8%26needsadmin%3Dfalse/update2/installers/ChromeSetup.exe