CVE-2010-3112: Buffer Overflow
Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
Which Chrome versions are affected?
Google Chrome versions before 5.0.375.127 are affected. The provided data does not identify affected operating systems or platforms.
Can this be exploited remotely without authentication?
The vector is network-based, the attack complexity is low, and no authentication is required according to the supplied severity vector. The description does not disclose the specific vectors used to trigger the file-dialog flaw.
What is the potential impact?
An attacker may cause a denial of service through memory corruption. The description also states that unspecified additional impact may be possible, while the severity vector indicates potential compromise of confidentiality, integrity, and availability.
What should be done if an affected version is in use?
Update Chrome to 5.0.375.127 or a later version. No compensating controls or temporary mitigations are provided in the available data.