CVE-2010-1773: High severity google chrome vulnerability
An off by one memory read out of bounds issue exists in WebKit's handling of HTML lists. Visiting a maliciously crafted website may lead to an unexpected application termination or the disclosure of the contents of memory. This issue is addressed through improved bounds checking.
References:
Bugzilla: https://bugs.webkit.org/showbug.cgi?id=39508 Trac: http://trac.webkit.org/changeset/59950
Acknowledgements:
Red Hat would like to thank Drew Yao of Apple Product Security for responsibly reporting this issue.
Other sources
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1773?
CVE-2010-1773 is considered a high severity vulnerability due to its potential to cause application termination or memory content disclosure.
How do I fix CVE-2010-1773?
To fix CVE-2010-1773, ensure that you update Google Chrome and your operating system to the latest versions that address the vulnerability.
Which software is affected by CVE-2010-1773?
CVE-2010-1773 affects various versions of Google Chrome, Red Hat Enterprise Linux, Ubuntu, and openSUSE.
What type of vulnerability is CVE-2010-1773?
CVE-2010-1773 is an off-by-one memory read out of bounds vulnerability in WebKit's HTML list handling.
What can happen if I visit a malicious website related to CVE-2010-1773?
Visiting a malicious website that exploits CVE-2010-1773 may lead to an unexpected application crash or reveal sensitive memory data.