Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by leveraging the ability to run a crafted program in the NaCl sandbox.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome‘NaClSandbox::InitializeLayerTwoSandbox’安全漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 Google Chrome 42.0.2311.90之前版本的components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc文件中的‘NaClSandbox::InitializeLayerTwoSandbox’函数存在安全漏洞,该漏洞源于Native Client程序没有执行RLIMIT_AS和RLIMIT_DATA限制。远程攻击者可利用该漏洞实施row-hammer攻
CVSS Information
N/A
Vulnerability Type
N/A