First published: Tue Jun 01 2010(Updated: )
Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | =1.0.154.48 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2120 has a moderately high severity as it allows remote attackers to consume resources and cause a denial of service.
To fix CVE-2010-2120, update Google Chrome to a version that has incorporated security patches that address this vulnerability.
Users running Google Chrome version 1.0.154.48 are specifically affected by CVE-2010-2120.
CVE-2010-2120 represents a denial of service attack caused by infinite loops in JavaScript creating invalid IFRAME elements.
Yes, CVE-2010-2120 can be exploited remotely by sending malicious JavaScript code to an unsuspecting user.