CVE-2010-4206: High severity Google Chrome vulnerability
Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SVG document, related to effects in the application of filters.
Other sources
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4206 to the following vulnerability:
Name: CVE-2010-4206 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4206 Assigned: 20101105 Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=60688 Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
Upstream Bugzilla: https://bugs.webkit.org/showbug.cgi?id=48371 Trac: http://trac.webkit.org/changeset/70652
Google Chrome before 7.0.517.44 accesses memory at an out-of-bounds array index during processing of an SVG document, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4206?
CVE-2010-4206 has a high severity rating due to the potential for denial of service and arbitrary code execution.
How do I fix CVE-2010-4206?
The fix for CVE-2010-4206 involves updating Google Chrome to version 7.0.517.44 or later, or updating WebKitGTK+ to version 1.2.6 or later.
What software is affected by CVE-2010-4206?
CVE-2010-4206 affects Google Chrome versions prior to 7.0.517.44, WebKitGTK+ versions prior to 1.2.6, and Fedora 13.
What types of attacks can exploit CVE-2010-4206?
CVE-2010-4206 can be exploited using specially crafted content that leads to a denial of service or potentially allows arbitrary code execution.
Is there a workaround for CVE-2010-4206?
There are no known effective workarounds for CVE-2010-4206 other than applying the necessary software updates.