---
title: "CVE-2010-4577\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2010-4577?format=md
keywords: index, follow
---

# CVE-2010-4577

Publication date 21 December 2010

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2010-4577?format=md#impact-score)

Toggle side navigation

## Description

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in
WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before
8.0.552.343, webkitgtk before 1.2.6, and other products does not properly
parse Cascading Style Sheets (CSS) token sequences, which allows remote
attackers to cause a denial of service (out-of-bounds read) via a crafted
local font, related to "Type Confusion."

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 11.04 natty | Fixed 8.0.552.224~r68599-0ubuntu1 |
| 10.10 maverick | Fixed 8.0.552.224~r68599-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 8.0.552.224~r68599-0ubuntu0.10.04.1 |
| 9.10 karmic | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |
| webkit | 11.04 natty | Not affected |
| 10.10 maverick | Fixed 1.2.7-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 1.2.7-0ubuntu0.10.04.1 |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4577)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2010-4577)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2010-4577)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2010-4577)

### Related Ubuntu Security Notices (USN)

+ [USN-1195-1](https://usn.ubuntu.com/USN-1195-1)
+ WebKit vulnerabilities
+ 23 August 2011

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2010-4577>
