SB2010092901 - Input validation error in webkit (Alpine package)
Published: September 29, 2010
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2010-2646)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
Remediation
Install update from vendor's website.