CVE-2010-3254: Integer Overflow
Published Sep 7, 2010
·Updated
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected Software
1 affected component
Google Chrome<6.0.472.53
Remediation
Patch Available
Event History
Sep 7, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
Which Chrome versions are affected?
Google Chrome versions before 6.0.472.53 are affected. Updating to version 6.0.472.53 or later addresses the issue.
2
Does exploitation require authentication or local access?
No. The vulnerability is remotely exploitable and requires no authentication, according to the listed attack vector and authentication requirements.
3
What impact could successful exploitation have?
An attacker may cause a denial of service and could potentially have other unspecified impact. The severity vector indicates potential impact to confidentiality, integrity, and availability.