CVE-2015-3335: High severity google chrome (trace event) vulnerability
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandboxlinux/naclsandboxlinux.cc in Google Chrome before 42.0.2311.90 does not have RLIMITAS and RLIMITDATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by leveraging the ability to run a crafted program in the NaCl sandbox.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3335?
CVE-2015-3335 has a medium severity rating due to its potential to allow remote attackers to exploit vulnerabilities in the Native Client sandboxing.
How do I fix CVE-2015-3335?
To fix CVE-2015-3335, update Google Chrome to version 42.0.2311.90 or later which contains the necessary security patches.
What is the impact of CVE-2015-3335?
The impact of CVE-2015-3335 could potentially allow a remote attacker to manipulate the memory limits of Native Client processes.
Which versions of Google Chrome are affected by CVE-2015-3335?
Google Chrome versions prior to 42.0.2311.90 are affected by CVE-2015-3335.
What platforms are vulnerable to CVE-2015-3335?
CVE-2015-3335 affects Google Chrome on Linux distributions like SUSE Linux versions 13.1 and 13.2.