ID

VAR-E-201103-0867


CVE

cve_id:CVE-2011-1290

Trust: 0.3

sources: BID: 46849

TITLE

WebKit Style Handling Memory Corruption Vulnerability

Trust: 0.3

sources: BID: 46849

DESCRIPTION

WebKit is prone to a memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Successful exploits will allow attackers to execute arbitrary code in the context of the browser. Failed exploit attempts will result in a denial-of-service condition.
NOTE: This issue was previously discussed in BID 46833 (Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities), but has been given its own record to better document it.

Trust: 0.3

sources: BID: 46849

AFFECTED PRODUCTS

vendor:researchmodel:in motion blackberry torchscope:eqversion:98000

Trust: 0.3

vendor:researchmodel:in motion blackberry stylescope:eqversion:96700

Trust: 0.3

vendor:researchmodel:in motion blackberry pearlscope:eqversion:91000

Trust: 0.3

vendor:researchmodel:in motion blackberry pearlscope:eqversion:81000

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:6.0

Trust: 0.3

vendor:researchmodel:in motion blackberry curvescope:eqversion:93000

Trust: 0.3

vendor:researchmodel:in motion blackberry curvescope:eqversion:83000

Trust: 0.3

vendor:researchmodel:in motion blackberry browserscope:eqversion:0

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:97800

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:97005.0.0.593

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:88004.2

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:88004.1

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:88000

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:87204.2

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:87204.1

Trust: 0.3

vendor:researchmodel:in motion blackberry 8700rscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 8700fscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 8700cscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:83204.2

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:83204.1

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7780

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7750

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7730

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7520

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7290

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7280

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:72700

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7250

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:72304.0

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:72303.8

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:72303.7.1.41

Trust: 0.3

vendor:researchmodel:in motion blackberry 7130escope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 7105tscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7100x

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:7100v

Trust: 0.3

vendor:researchmodel:in motion blackberry 7100tscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 7100rscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 7100iscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberry 7100gscope: - version: -

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:9700

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:9650

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:8530

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:8520

Trust: 0.3

vendor:researchmodel:in motion blackberryscope:eqversion:8330

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:9.0.597.94

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:9.0.597.84

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:9.0.597.107

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.128

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:10.0.648.127

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipselscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux m68kscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux hppascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armelscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linux alphascope:eqversion:5.0

Trust: 0.3

vendor:debianmodel:linuxscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.1.2

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.5

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.5

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.4

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.4

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.3

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:4.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10.2

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10.1

Trust: 0.3

vendor:applemodel:itunesscope:eqversion:10

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.3

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.6

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.5

Trust: 0.3

vendor:applemodel:ios betascope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.0

Trust: 0.3

vendor:googlemodel:chromescope:neversion:10.0.648.133

Trust: 0.3

vendor:applemodel:safari for windowsscope:neversion:5.0.5

Trust: 0.3

vendor:applemodel:safariscope:neversion:5.0.5

Trust: 0.3

vendor:applemodel:itunesscope:neversion:10.2.2

Trust: 0.3

vendor:applemodel:iosscope:neversion:4.3.2

Trust: 0.3

vendor:applemodel:iosscope:neversion:4.2.7

Trust: 0.3

sources: BID: 46849

EXPLOIT

This issue was successfully exploited at CanSecWest's 2011 Pwn2Own contest on a Blackberry device. The exploit is not known to be public or in the wild.
NOTE: To exploit this issue through iTunes, an attacker must first execute a successful man-in-the-middle attack.

Trust: 0.3

sources: BID: 46849

PRICE

Free

Trust: 0.3

sources: BID: 46849

TYPE

Unknown

Trust: 0.3

sources: BID: 46849

CREDITS

Vincenzo Iozzo, Ralf Philipp Weinmann and Willem Pinckaers

Trust: 0.3

sources: BID: 46849

EXTERNAL IDS

db:ZDIid:ZDI-11-104

Trust: 0.3

db:NVDid:CVE-2011-1290

Trust: 0.3

db:BIDid:46849

Trust: 0.3

sources: BID: 46849

REFERENCES

url:http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates.html

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/zdi-11-104/

Trust: 0.3

url:http://threatpost.com/en_us/blogs/iphone-blackberry-fall-second-day-pwn2own-031011

Trust: 0.3

url:http://btsc.webapps.blackberry.com/btsc/search.do?cmd=displaykc&doctype=kc&externalid=kb26132

Trust: 0.3

url:http://lists.apple.com/archives/security-announce/2011/apr/msg00004.html

Trust: 0.3

url:http://www.rim.net/

Trust: 0.3

url:http://www.google.com/chrome

Trust: 0.3

url:http://www.blackberry.com/btsc/dynamickc.do?externalid=kb26132&sliceid=1&command=show&forward=nonthreadedkc&kcid=kb26132

Trust: 0.3

url:http://www.webkit.org/

Trust: 0.3

sources: BID: 46849

SOURCES

db:BIDid:46849

LAST UPDATE DATE

2022-07-27T09:47:49.964000+00:00


SOURCES UPDATE DATE

db:BIDid:46849date:2011-10-11T19:10:00

SOURCES RELEASE DATE

db:BIDid:46849date:2011-03-10T00:00:00