Vulnerabilities > CVE-2010-4041 - Multiple Security vulnerability in Google Chrome prior to 7.0.517.41
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
Vulnerable Configurations
Oval
accepted | 2012-10-22T04:02:13.688-04:00 | ||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||
description | The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors. | ||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:14201 | ||||||||||||||||||||||||||||||||
status | deprecated | ||||||||||||||||||||||||||||||||
submitted | 2011-11-25T18:06:47.000-05:00 | ||||||||||||||||||||||||||||||||
title | DEPRECATED: The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors. | ||||||||||||||||||||||||||||||||
version | 50 |
References
- http://code.google.com/p/chromium/issues/detail?id=54794
- http://googlechromereleases.blogspot.com/2010/10/stable-channel-update.html
- http://secunia.com/advisories/41888
- http://www.securityfocus.com/bid/44241
- http://www.vupen.com/english/advisories/2010/2731
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14201