CVE-2010-1823
Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.28% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- google/chrome · apple/itunes · apple/safari
- Source
- product-security@apple.com
References
- http://code.google.com/p/chromium/issues/detail?id=50250Issue Tracking, Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.htmlVendor Advisory
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://support.apple.com/kb/HT4808Third Party Advisory
- http://support.apple.com/kb/HT4981Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=43055Permissions Required
- https://bugs.webkit.org/show_bug.cgi?id=44533Issue Tracking, Patch, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7405Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=50250Issue Tracking, Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.htmlVendor Advisory
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00000.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://support.apple.com/kb/HT4808Third Party Advisory
- http://support.apple.com/kb/HT4981Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=43055Permissions Required
- https://bugs.webkit.org/show_bug.cgi?id=44533Issue Tracking, Patch, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7405Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.