CVE-2010-0649: Integer Overflow
Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscallserver.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0649?
CVE-2010-0649 has a medium severity rating due to potential heap memory corruption and denial of service conditions.
How do I fix CVE-2010-0649?
To fix CVE-2010-0649, users should update Google Chrome to version 4.0.249.89 or later.
What impact can CVE-2010-0649 have on my system?
CVE-2010-0649 can lead to denial of service conditions, potentially allowing attackers to crash the affected application.
Which versions of Google Chrome are affected by CVE-2010-0649?
CVE-2010-0649 affects Google Chrome versions prior to 4.0.249.89, including early beta releases.
Is exploiting CVE-2010-0649 difficult for attackers?
Exploiting CVE-2010-0649 may require some technical knowledge, but the vulnerability poses a risk through rendered web content.