LWN.net Logo

chromium: multiple vulnerabilities

Package(s):chromium CVE #(s):
Created:December 20, 2010 Updated:December 22, 2010
Description: From the Gentoo advisory:

Multiple vulnerabilities were found in Chromium.

A remote attacker could trick a user to perform a set of UI actions that trigger a possibly exploitable crash, leading to execution of arbitrary code or a Denial of Service.

It was also possible for an attacker to entice a user to visit a specially-crafted web page that would trigger one of the vulnerabilities, leading to execution of arbitrary code within the confines of the sandbox, successful Cross-Site Scripting attacks, violation of the same-origin policy, successful website spoofing attacks, information leak, or a Denial of Service. An attacker could also trick a user to perform a set of UI actions that might result in a successful website spoofing attack.

Alerts:
Gentoo 201012-01 2010-12-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds