CVE-2010-2651: Buffer Overflow
Published Jul 6, 2010
·Updated
The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly perform style rendering, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected Software
1 affected component
Google Chrome<5.0.375.99
Remediation
Patch Available
Event History
Jul 6, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Which Chrome installations are affected?
Google Chrome versions before 5.0.375.99 are affected. The issue is in the browser's CSS implementation.
2
Does exploitation require authentication or local access?
No. The supplied CVSS vector indicates network attack access with no authentication required, although attack complexity is rated medium.
3
What could an attacker achieve?
A remote attacker may cause a denial of service through memory corruption. The advisory also states that unspecified additional impact may be possible.
4
What is the recommended remediation?
Apply the available patch by updating Chrome to a version that is not before 5.0.375.99.