Vulnerabilities > CVE-2010-4041 - Unspecified vulnerability in Google Chrome
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
Vulnerable Configurations
Oval
accepted | 2012-10-22T04:02:13.688-04:00 | ||||||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||||||
description | The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors. | ||||||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:14201 | ||||||||||||||||||||||||||||||||
status | deprecated | ||||||||||||||||||||||||||||||||
submitted | 2011-11-25T18:06:47.000-05:00 | ||||||||||||||||||||||||||||||||
title | DEPRECATED: The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors. | ||||||||||||||||||||||||||||||||
version | 50 |
References
- http://code.google.com/p/chromium/issues/detail?id=54794
- http://secunia.com/advisories/41888
- http://www.vupen.com/english/advisories/2010/2731
- http://googlechromereleases.blogspot.com/2010/10/stable-channel-update.html
- http://www.securityfocus.com/bid/44241
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14201