The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in...
Vulnerability Description
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4577
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.html
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html
- http://secunia.com/advisories/42648
- https://bugzilla.redhat.com/show_bug.cgi?id=667025
- http://www.vupen.com/english/advisories/2011/0216
- https://bugs.webkit.org/show_bug.cgi?id=49883
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13953
- http://secunia.com/advisories/43086
- http://code.google.com/p/chromium/issues/detail?id=63866
- http://www.redhat.com/support/errata/RHSA-2011-0177.html
- http://trac.webkit.org/changeset/72685/trunk/WebCore/css/CSSParser.cpp
- http://trac.webkit.org/changeset/72685
- http://www.debian.org/security/2011/dsa-2188
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml
- http://www.securityfocus.com/bid/45722
More from google
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.