CVE-2010-1792: Buffer Overflow
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1792?
CVE-2010-1792 has a high severity level due to its potential to allow remote attackers to execute arbitrary code.
How do I fix CVE-2010-1792?
To fix CVE-2010-1792, update your Apple Safari browser or WebKit to versions that are not vulnerable, specifically Safari 5.0.1 or later and WebKitGTK 1.2.6 or later.
Which versions of Safari are affected by CVE-2010-1792?
Affected versions of Safari include versions prior to 5.0.1 on Mac OS X and prior to 4.1.1 on Windows.
What types of attacks can CVE-2010-1792 lead to?
CVE-2010-1792 can lead to arbitrary code execution or denial of service through memory corruption.
Is there a workaround for CVE-2010-1792?
A temporary workaround for CVE-2010-1792 is to avoid opening untrusted websites in Safari until an update is applied.