CVE-2010-3113
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.90%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.90% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- google/chrome · webkitgtk/webkitgtk · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=628032Issue Tracking, Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=49596Issue Tracking, Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlVendor Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
- http://trac.webkit.org/changeset/63865Patch, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44199Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0216Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11901Third Party Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=628032Issue Tracking, Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=49596Issue Tracking, Patch, Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlVendor Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
- http://trac.webkit.org/changeset/63865Patch, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44199Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0216Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11901Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.