First published: Fri Sep 24 2010(Updated: )
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <6.0.472.59 | |
iTunes | <10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1824 is considered a critical vulnerability due to its potential to allow remote code execution.
CVE-2010-1824 affects Apple iTunes versions before 10.2, Google Chrome versions before 6.0.472.59, and Apple Safari.
To fix CVE-2010-1824, update Google Chrome to version 6.0.472.59 or later and Apple iTunes to version 10.2 or later.
CVE-2010-1824 can be exploited to execute arbitrary code or to cause a denial of service.
The vulnerability is caused by a use-after-free issue related to SVG styles, the DOM tree, and error messages in WebKit.