CVE-2010-2298

Publication date 15 June 2010

Last updated 24 July 2024


Ubuntu priority

browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions via vectors involving fchdir and chdir calls.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
chromium-browser 10.04 LTS lucid
Not affected
9.10 karmic Not in release
9.04 jaunty Not in release
8.04 LTS hardy Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

chromium-specific