CVE-2010-4574
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a denial of service or possibly have unspecified other impact, via invalid pickle data.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.80% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- google/chrome · google/chrome os
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=56449Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlVendor Advisory
- http://secunia.com/advisories/42648Third Party Advisory
- http://src.chromium.org/viewvc/chrome?view=rev&revision=68033Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/45390Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14141Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=56449Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlVendor Advisory
- http://secunia.com/advisories/42648Third Party Advisory
- http://src.chromium.org/viewvc/chrome?view=rev&revision=68033Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/45390Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14141Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.