rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.
| Software | From | Fixed in |
|---|---|---|
| google / chrome | - | 5.0.375.70 |
| opensuse / opensuse | 11.2 | 11.2.x |
| opensuse / opensuse | 11.3 | 11.3.x |
| suse / suse_linux_enterprise_server | 11-sp1 | 11-sp1.x |
| suse / suse_linux_enterprise_desktop | 11-sp1 | 11-sp1.x |
| suse / suse_linux_enterprise_server | 10-sp3 | 10-sp3.x |
| suse / suse_linux_enterprise_desktop | 10-sp3 | 10-sp3.x |