CVE-2010-4577
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-843
- Affected
- google/chrome · webkitgtk/webkitgtk · google/chrome os · fedoraproject/fedora · debian/debian linux
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=63866Exploit, Issue Tracking, Mailing List
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlRelease Notes
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/42648Broken Link, Third Party Advisory
- http://secunia.com/advisories/43086Broken Link, Third Party Advisory
- http://trac.webkit.org/changeset/72685Mailing List, Patch
- http://trac.webkit.org/changeset/72685/trunk/WebCore/css/CSSParser.cppMailing List, Patch
- http://www.debian.org/security/2011/dsa-2188Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlBroken Link, Third Party Advisory
- http://www.securityfocus.com/bid/45722Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0216Broken Link, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=49883Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=667025Issue Tracking, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13953Broken Link, Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=63866Exploit, Issue Tracking, Mailing List
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlRelease Notes
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/42648Broken Link, Third Party Advisory
- http://secunia.com/advisories/43086Broken Link, Third Party Advisory
- http://trac.webkit.org/changeset/72685Mailing List, Patch
- http://trac.webkit.org/changeset/72685/trunk/WebCore/css/CSSParser.cppMailing List, Patch
- http://www.debian.org/security/2011/dsa-2188Mailing List, Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlBroken Link, Third Party Advisory
- http://www.securityfocus.com/bid/45722Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0216Broken Link, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=49883Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=667025Issue Tracking, Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13953Broken Link, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.