CVE-2010-3120: Buffer Overflow
Published Aug 24, 2010
·Updated
Google Chrome before 5.0.375.127 does not properly implement the Geolocation feature, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected Software
1 affected component
Google Chrome<5.0.375.127
Remediation
Patch Available
Event History
Aug 24, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
Which Chrome installations are affected?
Google Chrome versions before 5.0.375.127 are affected.
2
Does exploitation require user authentication or local access?
No. The reported vector is network-based, has low attack complexity, and requires no authentication.
3
What is the potential impact of successful exploitation?
An attacker may cause a denial of service through memory corruption, with unspecified additional impact possible. The vulnerability is rated critical with confidentiality, integrity, and availability impacts listed as complete.
4
What should teams do to remediate this issue?
Apply the available patch by updating Chrome to 5.0.375.127 or later.