CVE-2010-4574

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
22/12/2010
Last modified:
31/07/2020

Description

The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization validation, and cause a denial of service or possibly have unspecified other impact, via invalid pickle data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 8.0.552.224 (excluding)
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* 8.0.552.343 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:x64:*