CVE-2010-4577
Publication date 21 December 2010
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to “Type Confusion.”
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 11.04 natty |
Fixed 8.0.552.224~r68599-0ubuntu1
|
10.10 maverick |
Fixed 8.0.552.224~r68599-0ubuntu0.10.10.1
|
|
10.04 LTS lucid |
Fixed 8.0.552.224~r68599-0ubuntu0.10.04.1
|
|
9.10 karmic | Not in release | |
8.04 LTS hardy | Not in release | |
6.06 LTS dapper | Not in release | |
webkit | 11.04 natty |
Not affected
|
10.10 maverick |
Fixed 1.2.7-0ubuntu0.10.10.1
|
|
10.04 LTS lucid |
Fixed 1.2.7-0ubuntu0.10.04.1
|
|
8.04 LTS hardy | Ignored end of life |
Severity score breakdown
Parameter | Value |
---|---|
Base score |
|
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-1195-1
- WebKit vulnerabilities
- 23 August 2011