CVE-2010-2297: Code Injection
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2297?
CVE-2010-2297 has a high severity rating as it can cause a denial of service or arbitrary code execution.
How do I fix CVE-2010-2297?
To fix CVE-2010-2297, upgrade to Google Chrome version 5.0.375.70 or later.
What types of software are affected by CVE-2010-2297?
CVE-2010-2297 affects versions of Google Chrome before 5.0.375.70 and certain openSUSE and SUSE Linux Enterprise versions.
What impact does CVE-2010-2297 have on my system?
CVE-2010-2297 can lead to application crashes or potentially allow attackers to execute arbitrary code on the affected system.
Can older versions of browsers still be vulnerable due to CVE-2010-2297?
Yes, using older versions of Google Chrome or specified SUSE distributions can leave systems vulnerable to CVE-2010-2297.