First published: Tue Jun 15 2010(Updated: )
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <5.0.375.70 | |
SUSE Linux | =11.2 | |
SUSE Linux | =11.3 | |
SUSE Linux Enterprise Server | =11-sp1 | |
SUSE Linux Enterprise Desktop | =11-sp1 | |
SUSE Linux Enterprise Server | =10-sp3 | |
SUSE Linux Enterprise Desktop | =10-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2301 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2010-2301, update Google Chrome to version 5.0.375.70 or later.
CVE-2010-2301 affects Google Chrome versions earlier than 5.0.375.70.
CVE-2010-2301 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary scripts into a web page.
Yes, CVE-2010-2301 also affects certain versions of openSUSE and SUSE Linux Enterprise Desktop and Server.