First published: Mon Dec 13 2010(Updated: )
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <0:1.2.6-2.el6_0 | 0:1.2.6-2.el6_0 |
WebKitGTK WebKitGTK | <1.2.6 | |
Google Chrome OS | <8.0.552.343 | |
Google Chrome | <8.0.552.224 | |
Fedoraproject Fedora | =13 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.