CVE-2010-0664: Medium severity Google Chrome vulnerability
Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/childprocesssecuritypolicy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0664?
CVE-2010-0664 has a severity level that can result in denial of service through memory consumption and application crashes.
How do I fix CVE-2010-0664?
To fix CVE-2010-0664, upgrade Google Chrome to version 4.0.249.78 or later.
What versions of Google Chrome are affected by CVE-2010-0664?
CVE-2010-0664 affects multiple versions of Google Chrome prior to 4.0.249.78, including versions 0.2 to 3.x.
Can CVE-2010-0664 be exploited remotely?
Yes, CVE-2010-0664 can be exploited remotely by using specially crafted URLs.
What impact does CVE-2010-0664 have on my application?
The impact of CVE-2010-0664 can lead to a crash of the Google Chrome application.