CVE-2010-4204: Use After Free
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4204 to the following vulnerability:
Name: CVE-2010-4204 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4204 Assigned: 20101105 Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=60238 Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html Upstream Bugzilla: https://bugs.webkit.org/showbug.cgi?id=48281 Trac: http://trac.webkit.org/changeset/70517
Google Chrome before 7.0.517.44 accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Other sources
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4204?
CVE-2010-4204 is classified as a denial of service vulnerability that can potentially cause unspecified impacts.
How do I fix CVE-2010-4204?
To fix CVE-2010-4204, update Google Chrome to version 7.0.517.44 or later and upgrade webkitgtk to version 1.2.6-2.el6_0 or later.
What products are affected by CVE-2010-4204?
CVE-2010-4204 affects Google Chrome before version 7.0.517.44 and webkitgtk before version 1.2.6.
Can CVE-2010-4204 be exploited remotely?
Yes, CVE-2010-4204 can be exploited remotely to cause a denial of service.
What impact does CVE-2010-4204 have on users?
The impact of CVE-2010-4204 includes potential system crashes and instability when using affected browser versions.