CVE-2010-3114: Critical severity Google Chrome vulnerability
iCommon Vulnerabilities and Exposures assigned an identifier CVE-2010-3114 to the following vulnerability:
Name: CVE-2010-3114 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3114 Assigned: 20100824 Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=49628 Reference: CONFIRM: http://googlechromereleases.blogspot.com/2010/08/stable-channel-update19.html
The text-editing implementation in Google Chrome before 5.0.375.127 does not properly perform casts, which has unspecified impact and attack vectors.
This flaw also affects upstream WebKit:
https://bugs.webkit.org/showbug.cgi?id=42655 http://trac.webkit.org/changeset/63773
Other sources
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3114?
CVE-2010-3114 has been classified as having a significant severity level due to potential exploitation risks.
How do I fix CVE-2010-3114?
To fix CVE-2010-3114, users should update their affected software to the latest version released by the vendor.
What versions of Google Chrome are affected by CVE-2010-3114?
CVE-2010-3114 affects Google Chrome versions prior to 5.0.375.127.
Which operating systems are vulnerable to CVE-2010-3114?
CVE-2010-3114 affects Ubuntu Linux versions 9.10, 10.04, and 10.10.
What components of WebKitGTK+ are vulnerable to CVE-2010-3114?
CVE-2010-3114 impacts WebKitGTK+ versions prior to 1.2.6.