CVE-2010-2298

Publication date 15 June 2010

Last updated 24 July 2024


Ubuntu priority

Description

browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions via vectors involving fchdir and chdir calls.

Read the notes from the security team

Status

Package Ubuntu Release Status
chromium-browser 10.04 LTS lucid
Not affected
9.10 karmic Not in release
9.04 jaunty Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

chromium-specific


Access our resources on patching vulnerabilities