CVE-2010-4197: Use After Free
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4197 to the following vulnerability:
Name: CVE-2010-4197 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4197 Assigned: 20101105 Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=51602 Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
Upstream Bugzilla: https://bugs.webkit.org/showbug.cgi?id=48349 Trac: http://trac.webkit.org/changeset/70594
Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.
Other sources
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4197?
CVE-2010-4197 is rated as a high severity vulnerability.
How do I fix CVE-2010-4197?
To fix CVE-2010-4197, update Google Chrome or WebKitGTK+ to the latest available version.
Which software is affected by CVE-2010-4197?
CVE-2010-4197 affects versions of Google Chrome prior to 7.0.517.44, WebKitGTK+ prior to 1.2.6, and Fedora 13.
Is CVE-2010-4197 a local or remote vulnerability?
CVE-2010-4197 is classified as a remote vulnerability.
Can CVE-2010-4197 lead to code execution?
Yes, CVE-2010-4197 can potentially allow for arbitrary code execution.