CVE-2010-1772: Use After Free
A use after free issue exists in WebKit's handling of geolocation events. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handing of geolocation events.
References:
Bugzilla: https://bugs.webkit.org/showbug.cgi?id=39388 Trac: http://trac.webkit.org/changeset/59859
Acknowledgements:
Red Hat would like to thank Drew Yao of Apple Product Security for responsibly reporting this issue. Upstream acknowledges Justin Schuh as the original reporter.
Other sources
Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1772?
CVE-2010-1772 has a medium severity rating due to its potential for causing application crashes or arbitrary code execution.
How do I fix CVE-2010-1772?
To fix CVE-2010-1772, update your affected software to the latest version where the vulnerability has been addressed.
Which software is affected by CVE-2010-1772?
CVE-2010-1772 affects several software products including Google Chrome versions prior to 5.0.375.70 and multiple versions of Linux distributions such as Red Hat, Ubuntu, and openSUSE.
What can happen if I visit a malicious website related to CVE-2010-1772?
Visiting a maliciously crafted website related to CVE-2010-1772 may lead to unexpected application termination or allow for arbitrary code execution on your system.
What type of issue is CVE-2010-1772 categorized as?
CVE-2010-1772 is categorized as a use after free vulnerability in the handling of geolocation events.