First published: Sat Nov 06 2010(Updated: )
Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SVG document, related to effects in the application of filters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome (Trace Event) | <7.0.517.44 | |
Oracle Webkitgtk4-jsc | <1.2.6 | |
Fedora | =13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4206 has a high severity rating due to the potential for denial of service and arbitrary code execution.
The fix for CVE-2010-4206 involves updating Google Chrome to version 7.0.517.44 or later, or updating WebKitGTK+ to version 1.2.6 or later.
CVE-2010-4206 affects Google Chrome versions prior to 7.0.517.44, WebKitGTK+ versions prior to 1.2.6, and Fedora 13.
CVE-2010-4206 can be exploited using specially crafted content that leads to a denial of service or potentially allows arbitrary code execution.
There are no known effective workarounds for CVE-2010-4206 other than applying the necessary software updates.