CVE-2010-1773
Publication date 24 September 2010
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
qt4-x11 | ||
webkit | ||
Notes
jdstrand
qt4-x11 unmaintained upstream (see README.webkit for details) webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit.
mdeslaur
webkitkde is a wrapper around qt4-x11's webkit.
jdstrand
chromium-browser usually has its own CVEs for its own embedded webkit, but adjust it as needed
Severity score breakdown
Parameter | Value |
---|---|
Base score | 8.8 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |