Google Native Client (NaCl) contains a flaw related to super instructions not being marked during dynamic code modification. With specially crafted injected code, a context-dependent attacker can escape the sandbox.
Classification
Location:
Context Dependent
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Vuln Dependent,
Web Related
Solution
It has been reported that this issue has been fixed. Upgrade to revision 7712, or higher, to address this vulnerability.
Upgrade to Google Chrome version 17.0.963.56 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.