CVE-2010-3249: Critical severity google chrome (trace event) vulnerability
Published Sep 7, 2010
·Updated
Google Chrome before 6.0.472.53 does not properly implement SVG filters, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, related to a "stale pointer" issue.
Affected Software
1 affected component
Google Chrome<6.0.472.53
Remediation
Patch Available
Event History
Sep 7, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Which Chrome versions need to be remediated?
Google Chrome versions before 6.0.472.53 are affected. A patch is available, so update affected installations to a patched release.
2
Can this issue be exploited remotely without authentication?
Yes. The supplied vector indicates network-based exploitation with no authentication required, although the attack complexity is rated medium.
3
What security impact is associated with successful exploitation?
The issue can cause a denial of service and may have other unspecified impact. The provided severity vector rates confidentiality, integrity, and availability impact as complete.