Back to search
CVE-2015-3335
Published: Apr 19, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.90 does not have RLIMIT_AS and RLIMIT_DATA limits for Native Client (aka NaCl) processes, which might make it easier for remote attackers to conduct row-hammer attacks or have unspecified other impact by leveraging the ability to run a crafted program in the NaCl sandbox.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
72715
vdb-entry
x_refsource_BID
openSUSE-SU-2015:0748
vendor-advisory
x_refsource_SUSE
https://code.google.com/p/chromium/issues/detail?id=455839
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now