CVE-2010-0662: Integer Overflow
The ParamTraits<SkBitmap>::Read function in common/commonparamtraits.cc in Google Chrome before 4.0.249.78 does not use the correct variables in calculations designed to prevent integer overflows, which allows attackers to leverage renderer access to cause a denial of service or possibly have unspecified other impact via bitmap data, related to deserialization.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0662?
CVE-2010-0662 is classified as a medium to high severity vulnerability due to the potential for denial of service and possible untrusted access exploits.
How do I fix CVE-2010-0662?
To fix CVE-2010-0662, update Google Chrome to version 4.0.249.78 or later.
What are the affected versions for CVE-2010-0662?
CVE-2010-0662 affects Google Chrome versions prior to 4.0.249.78 and specific versions like 0.2.149.27, 1.0.154.36, and others listed in its CPE.
What type of exploitation is possible with CVE-2010-0662?
CVE-2010-0662 can allow attackers to exploit renderer access to potentially cause a denial of service.
Is CVE-2010-0662 still a significant risk today?
CVE-2010-0662 is largely mitigated today with newer versions of Google Chrome, making it less of a significant risk for current users.