CVE-2010-4577: High severity google chrome vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4577 to the following vulnerability:
Name: CVE-2010-4577 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4577 Assigned: 20101221 Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=63866 Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates13.html
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
Upstream: Bugzilla: https://bugs.webkit.org/showbug.cgi?id=49883 Trac: http://trac.webkit.org/changeset/72685
This is fixed in webkitgtk 1.2.6
Other sources
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4577?
CVE-2010-4577 is considered a critical vulnerability due to its ability to allow remote attackers to execute arbitrary code.
How do I fix CVE-2010-4577?
To fix CVE-2010-4577, update Google Chrome to version 8.0.552.224 or later, or upgrade to the latest version of the affected webkitgtk packages.
What software is affected by CVE-2010-4577?
CVE-2010-4577 affects Google Chrome versions before 8.0.552.224, Chrome OS versions before 8.0.552.343, and webkitgtk versions before 1.2.6.
What type of vulnerability is CVE-2010-4577?
CVE-2010-4577 is a cross-site scripting vulnerability that exploits improper parsing of CSS token sequences.
Who can exploit CVE-2010-4577?
CVE-2010-4577 can be exploited by remote attackers, potentially compromising user systems without user interaction.