First published: Tue Jan 25 2011(Updated: )
WebKitGTK+ is the port of the portable web rendering engine WebKit to the<br>GTK+ platform.<br>Multiple memory corruption flaws were found in WebKit. Malicious web<br>content could cause an application using WebKitGTK+ to crash or,<br>potentially, execute arbitrary code with the privileges of the user running<br>the application. (CVE-2010-1782, CVE-2010-1783, CVE-2010-1784,<br>CVE-2010-1785, CVE-2010-1787, CVE-2010-1788, CVE-2010-1790, CVE-2010-1792,<br>CVE-2010-1807, CVE-2010-1814, CVE-2010-3114, CVE-2010-3116, CVE-2010-3119,<br>CVE-2010-3255, CVE-2010-3812, CVE-2010-4198)<br>Multiple use-after-free flaws were found in WebKit. Malicious web content<br>could cause an application using WebKitGTK+ to crash or, potentially,<br>execute arbitrary code with the privileges of the user running the<br>application. (CVE-2010-1780, CVE-2010-1786, CVE-2010-1793, CVE-2010-1812,<br>CVE-2010-1815, CVE-2010-3113, CVE-2010-3257, CVE-2010-4197, CVE-2010-4204)<br>Two array index errors, leading to out-of-bounds memory reads, were found<br>in WebKit. Malicious web content could cause an application using<br>WebKitGTK+ to crash. (CVE-2010-4206, CVE-2010-4577)<br>A flaw in WebKit could allow malicious web content to trick a user into<br>thinking they are visiting the site reported by the location bar, when the<br>page is actually content controlled by an attacker. (CVE-2010-3115)<br>It was found that WebKit did not correctly restrict read access to images<br>created from the "canvas" element. Malicious web content could allow a<br>remote attacker to bypass the same-origin policy and potentially access<br>sensitive image data. (CVE-2010-3259)<br>A flaw was found in the way WebKit handled DNS prefetching. Even when it<br>was disabled, web content containing certain "link" elements could cause<br>WebKitGTK+ to perform DNS prefetching. (CVE-2010-3813)<br>Users of WebKitGTK+ should upgrade to these updated packages, which contain<br>WebKitGTK+ version 1.2.6, and resolve these issues. All running<br>applications that use WebKitGTK+ must be restarted for this update to take<br>effect.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-debuginfo | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-debuginfo | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-devel | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-devel | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-doc | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
redhat/webkitgtk-doc | <1.2.6-2.el6_0 | 1.2.6-2.el6_0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.