ID

VAR-201009-0260


CVE

CVE-2010-1824


TITLE

Google Chrome Used in Webkit Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2010-002837

DESCRIPTION

Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages. Google Chrome Used in Webkit Is SVG style Service operation is interrupted due to incomplete processing (DoS) There are vulnerabilities that can be in a state or are otherwise unaffected.Service disruption by a third party (DoS) You may be put into a state or affected by other details. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the methodology the application takes to inform a user about an error while parsing a malformed document. When displaying the error message, the application will append the message to the current instance of the DOM tree causing another element to be removed which will lead to the styles being recalculated. When the styles are recalculated the application will access the initially freed element which can lead to code execution under the context of the application. WebKit is prone to multiple memory-corruption vulnerabilities. An attacker may exploit these issues by enticing victims into viewing a malicious webpage. This BID is being retired. The following individual records exists to better document the issues: 46684 WebKit CVE-2011-0111 Unspecified Memory Corruption Vulnerability 46686 WebKit CVE-2011-0117 Unspecified Memory Corruption Vulnerability 46687 WebKit CVE-2011-0118 Unspecified Memory Corruption Vulnerability 46688 WebKit CVE-2011-0119 Unspecified Memory Corruption Vulnerability 46689 WebKit CVE-2011-0141 Unspecified Memory Corruption Vulnerability 46690 WebKit CVE-2011-0136 Unspecified Memory Corruption Vulnerability 46691 WebKit CVE-2011-0114 Unspecified Memory Corruption Vulnerability 46692 WebKit CVE-2011-0128 Unspecified Memory Corruption Vulnerability 46693 WebKit CVE-2011-0129 Unspecified Memory Corruption Vulnerability 46694 WebKit CVE-2011-0120 Unspecified Memory Corruption Vulnerability 46695 WebKit CVE-2011-0143 Unspecified Memory Corruption Vulnerability 46696 WebKit CVE-2011-0121 Unspecified Memory Corruption Vulnerability 46698 WebKit CVE-2011-0123 Unspecified Memory Corruption Vulnerability 46699 WebKit CVE-2011-0144 Unspecified Memory Corruption Vulnerability 46700 WebKit CVE-2011-0130 Unspecified Memory Corruption Vulnerability 46701 WebKit CVE-2011-0125 Unspecified Memory Corruption Vulnerability 46702 WebKit CVE-2011-0147 Unspecified Memory Corruption Vulnerability 46703 WebKit CVE-2011-0164 Unspecified Memory Corruption Vulnerability 46704 WebKit CVE-2011-0131 Unspecified Memory Corruption Vulnerability 46705 WebKit CVE-2011-0127 Unspecified Memory Corruption Vulnerability 46706 WebKit CVE-2011-0142 Unspecified Memory Corruption Vulnerability 46707 WebKit CVE-2011-0137 Unspecified Memory Corruption Vulnerability 46708 WebKit CVE-2011-0148 Unspecified Memory Corruption Vulnerability 46709 WebKit CVE-2011-0135 Unspecified Memory Corruption Vulnerability 46710 WebKit CVE-2011-0145 Unspecified Memory Corruption Vulnerability 46711 WebKit CVE-2011-0134 Unspecified Memory Corruption Vulnerability 46712 WebKit CVE-2011-0139 Unspecified Memory Corruption Vulnerability 46713 WebKit CVE-2011-0138 Unspecified Memory Corruption Vulnerability 46714 WebKit CVE-2011-0140 Unspecified Memory Corruption Vulnerability 46715 WebKit CVE-2011-0146 Unspecified Memory Corruption Vulnerability 46716 WebKit CVE-2011-0165 Unspecified Memory Corruption Vulnerability 46717 WebKit CVE-2011-0150 Unspecified Memory Corruption Vulnerability 46718 WebKit CVE-2011-0152 Unspecified Memory Corruption Vulnerability 46719 WebKit CVE-2011-0151 Unspecified Memory Corruption Vulnerability 46720 WebKit CVE-2011-0153 Unspecified Memory Corruption Vulnerability 46721 WebKit CVE-2011-0155 Unspecified Memory Corruption Vulnerability 46722 WebKit CVE-2011-0168 Unspecified Memory Corruption Vulnerability 46723 WebKit CVE-2011-0122 Unspecified Memory Corruption Vulnerability 46724 WebKit CVE-2011-0156 Unspecified Memory Corruption Vulnerability 46725 WebKit CVE-2011-0124 Unspecified Memory Corruption Vulnerability 46726 WebKit CVE-2011-0112 Unspecified Memory Corruption Vulnerability 46727 WebKit CVE-2011-0126 Unspecified Memory Corruption Vulnerability 46728 WebKit CVE-2011-0113 Unspecified Memory Corruption Vulnerability 46744 WebKit CVE-2011-0149 'HTMLBRElement' Style Memory Corruption Vulnerability 46745 WebKit CVE-2011-0154 Javascript 'sort()' Method Memory Corruption Vulnerability 46746 WebKit Range Object Remote Code Execution Vulnerability 46747 WebKit CVE-2011-0116 'setOuterText()' Method Memory Corruption Remote Code Execution Vulnerability 46748 WebKit 'Runin' Box CVE-2011-0132 Use-After-Free Memory Corruption Vulnerability 46749 WebKit CVE-2011-0133 Glyph Data Memory Corruption Vulnerability. NOTE: This issue was previously discussed in BID 43228 (Google Chrome prior to 6.0.472.59 Multiple Security Vulnerabilities) but has been given its own record to better document it. WebKit is a set of open source web browser engines jointly developed by companies such as KDE, Apple (Apple), and Google (Google), and is currently used by browsers such as Apple Safari and Google Chrome. ---------------------------------------------------------------------- Get a tax break on purchases of Secunia Solutions! If you are a U.S. company, you may be qualified for a tax break for your software purchases. Learn more at: http://secunia.com/products/corporate/vim/section_179/ ---------------------------------------------------------------------- TITLE: Apple iTunes Multiple Vulnerabilities SECUNIA ADVISORY ID: SA43582 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/43582/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=43582 RELEASE DATE: 2011-03-03 DISCUSS ADVISORY: http://secunia.com/advisories/43582/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/43582/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=43582 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Multiple vulnerabilities have been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system. 1) Some errors exists due to the use of a vulnerable libpng library. For more information: SA40302 2) An array indexing error in the CoreGraphics library (ImageIO) when processing the International Color Consortium (ICC) profile within a JPEG image can be exploited to corrupt heap-based memory. 3) An error in the libTIFF library when handling JPEG encoded TIFF images can be exploited to cause a buffer overflow. 4) A boundary error in the libTIFF library when handling CCITT Group 4 encoded TIFF images. For more information: SA43593 5) A double free error in the libxml library when handling XPath expressions. For more information: SA42721 6) An error exists in the libxml library when traversing the XPath. 9) An error in the WebKit component when handling a DOM level 2 range object can be exploited to corrupt memory by manipulating the DOM via an event listener. 10) A use-after-free error in the "setOuterText()" method in the htmlelement library (WebKit) when tracking DOM manipulations can be exploited to dereference freed memory. 11) A use-after-free error in the WebKit component when promoting a run-in element can be exploited to dereference freed memory. 12) An error in the WebKit component when performing layout operations for a floating block of a pseudo-element can be exploited to dereference uninitialised glyph data. 13) An error in the WebKit component when parsing a Root HTMLBRElement element can be exploited to call an unmapped dangling pointer. 14) An error in the Javascript array "sort()" method (WebKit) can be exploited to manipulate elements outside of the array's boundary. SOLUTION: Update to version 10.2. Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ PROVIDED AND/OR DISCOVERED BY: 2) Andrzej Dyjak via iDefense VCP 3, 4) Reported by the vendor 8, 11 - 13) wushi of team509 via ZDI 9) J23 via ZDI 10, 14) An anonymous person via ZDI 11) Jose A. Vazquez via ZDI The vendor also credits: 5) Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences 6) Bui Quang Minh, Bkis 8) kuzcc 9) Emil A Eklund, Google Inc 13) SkyLined, Google Chrome Security Team The vendor provides a bundled list of credits for vulnerabilities in #7: Sergey Glazunov Andreas Kling, Nokia Yuzo Fujishima, Google Inc. Abhishek Arya (Inferno), Google, Inc. Mihai Parparita, Google, Inc. Emil A Eklund, Google, Inc. Michal Zalewski, Google, Inc. Chris Evans, Google Chrome Security Team SkyLined, Google Chrome Security Team Chris Rohlf, Matasano Security Aki Helin, OUSPG Dirk Schulze Slawomir Blazek David Bloom Famlam Jan Tosovsky Michael Gundlach ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT4554 iDefense VCP: http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=897 ZDI: http://www.zerodayinitiative.com/advisories/ZDI-11-095/ http://www.zerodayinitiative.com/advisories/ZDI-11-096/ http://www.zerodayinitiative.com/advisories/ZDI-11-097/ http://www.zerodayinitiative.com/advisories/ZDI-11-098/ http://www.zerodayinitiative.com/advisories/ZDI-11-099/ http://www.zerodayinitiative.com/advisories/ZDI-11-100/ http://www.zerodayinitiative.com/advisories/ZDI-11-101/ OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ EXPLOIT: Further details available in Customer Area: http://secunia.com/products/corporate/EVM/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . ---------------------------------------------------------------------- Secure your corporate defenses and reduce complexity in handling vulnerability threats with the new Secunia Vulnerability Intelligence Manager (VIM). For more information: SA32349 SA33495 SA35095 SA35379 SA35411 SA35449 SA35758 SA36269 SA36677 SA37273 SA37346 SA37769 SA38061 SA38545 SA38932 SA39029 SA39091 SA39384 SA39661 SA39937 SA40002 SA40072 SA40105 SA40112 SA40148 SA40196 SA40257 SA40664 SA40783 SA41014 SA41085 SA41242 SA41328 SA41390 SA41443 SA41535 SA41841 SA41888 SA41968 SA42151 SA42264 SA42290 SA42312 SA42443 SA42461 SA42658 SA42769 SA42886 SA42956 SA43053 SOLUTION: Apply updated packages via YaST Online Update or the SUSE FTP server. -- Vendor Response: Apple has issued an update to correct this vulnerability. More details can be found at: http://support.apple.com/kb/HT4554 -- Disclosure Timeline: 2010-10-18 - Vulnerability reported to vendor 2011-03-02 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * wushi of team509 -- About the Zero Day Initiative (ZDI): Established by TippingPoint, The Zero Day Initiative (ZDI) represents a best-of-breed model for rewarding security researchers for responsibly disclosing discovered vulnerabilities. Researchers interested in getting paid for their security research through the ZDI can find more information and sign-up at: http://www.zerodayinitiative.com The ZDI is unique in how the acquired vulnerability information is used. TippingPoint does not re-sell the vulnerability details or any exploit code. Instead, upon notifying the affected product vendor, TippingPoint provides its customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available. Furthermore, with the altruistic aim of helping to secure a broader user base, TippingPoint provides this vulnerability information confidentially to security vendors (including competitors) who have a vulnerability protection or mitigation product. Our vulnerability disclosure policy is available online at: http://www.zerodayinitiative.com/advisories/disclosure_policy/ Follow the ZDI on Twitter: http://twitter.com/thezdi _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ . ========================================================================== Ubuntu Security Notice USN-1195-1 August 23, 2011 webkit vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: Multiple security vulnerabilities were fixed in WebKit. Software Description: - webkit: Web content engine library for GTK+ Details: A large number of security issues were discovered in the WebKit browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: libwebkit-1.0-2 1.2.7-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: libwebkit-1.0-2 1.2.7-0ubuntu0.10.04.1 After a standard system update you need to restart any applications that use WebKit, such as Epiphany and Midori, to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-1195-1 CVE-2010-1824, CVE-2010-2646, CVE-2010-2651, CVE-2010-2900, CVE-2010-2901, CVE-2010-3120, CVE-2010-3254, CVE-2010-3812, CVE-2010-3813, CVE-2010-4040, CVE-2010-4042, CVE-2010-4197, CVE-2010-4198, CVE-2010-4199, CVE-2010-4204, CVE-2010-4206, CVE-2010-4492, CVE-2010-4493, CVE-2010-4577, CVE-2010-4578, CVE-2011-0482, CVE-2011-0778 Package Information: https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1 https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1

Trust: 3.24

sources: NVD: CVE-2010-1824 // JVNDB: JVNDB-2010-002837 // ZDI: ZDI-11-095 // BID: 46654 // BID: 46677 // VULHUB: VHN-44429 // PACKETSTORM: 98876 // PACKETSTORM: 97846 // PACKETSTORM: 98855 // PACKETSTORM: 104366

AFFECTED PRODUCTS

vendor:googlemodel:chromescope:ltversion:6.0.472.59

Trust: 1.8

vendor:applemodel:itunesscope:eqversion:10

Trust: 1.4

vendor:applemodel:itunesscope:ltversion:10.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:server v10.5.8

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:iosscope:eqversion:3.0 to 4.2.1 (iphone 3g after )

Trust: 0.8

vendor:applemodel:iosscope:eqversion:3.1 to 4.2/1 (ipod touch (3rd generation) after )

Trust: 0.8

vendor:applemodel:iosscope:eqversion:3.2 to 4.2.1 (ipad for )

Trust: 0.8

vendor:applemodel:ipadscope: - version: -

Trust: 0.8

vendor:applemodel:ipod touchscope: - version: -

Trust: 0.8

vendor:applemodel:webkitscope: - version: -

Trust: 0.7

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.5

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.3

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.2

Trust: 0.6

vendor:webkitmodel:open source project webkit r77705scope: - version: -

Trust: 0.6

vendor:webkitmodel:open source project webkit r52833scope: - version: -

Trust: 0.6

vendor:webkitmodel:open source project webkit r52401scope: - version: -

Trust: 0.6

vendor:webkitmodel:open source project webkit r51295scope: - version: -

Trust: 0.6

vendor:webkitmodel:open source project webkit r38566scope: - version: -

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.x

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:1.2.2-1

Trust: 0.6

vendor:webkitmodel:open source project webkitscope:eqversion:0

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.2.1

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.0.2

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.0.1.8

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.0.1

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.0

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.2

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:9.1

Trust: 0.6

vendor:applemodel:itunesscope:eqversion:10.1

Trust: 0.6

vendor:applemodel:itunesscope:neversion:10.2

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.404.1

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.405.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.403.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.401.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.399.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.406.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.400.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.404.0

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.404.2

Trust: 0.6

vendor:googlemodel:chromescope:eqversion:6.0.401.1

Trust: 0.6

vendor:ubuntumodel:linux powerpcscope:eqversion:10.10

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:10.10

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:10.10

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:10.10

Trust: 0.3

vendor:ubuntumodel:linux sparcscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux powerpcscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux i386scope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux armscope:eqversion:10.04

Trust: 0.3

vendor:ubuntumodel:linux amd64scope:eqversion:10.04

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:6.0.47255

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:5.0.375.55

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.2491064

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.2491059

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.2491036

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.249.1045

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.249.1042

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.0.249.89

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.0.249.78

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:6.0.472.53

Trust: 0.3

vendor:googlemodel:chromescope:eqversion:4.1.249.1044

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.1.2

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.5

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.5

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.4

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.3

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.3

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.2

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0.1

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:5.0

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.3

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.2

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1.1

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:4.0

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4.0

Trust: 0.3

vendor:applemodel:safari for windowsscope:eqversion:4

Trust: 0.3

vendor:applemodel:safari betascope:eqversion:4

Trust: 0.3

vendor:applemodel:safariscope:eqversion:4

Trust: 0.3

vendor:applemodel:mobile safariscope:eqversion:0

Trust: 0.3

vendor:applemodel:ipod touchscope:eqversion:0

Trust: 0.3

vendor:applemodel:iphonescope:eqversion:0

Trust: 0.3

vendor:applemodel:ipadscope:eqversion:0

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.0.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2.1

Trust: 0.3

vendor:applemodel:ios betascope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:4

Trust: 0.3

vendor:applemodel:iosscope:eqversion:3.2

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.1

Trust: 0.3

vendor:applemodel:iosscope:eqversion:2.0

Trust: 0.3

vendor:googlemodel:chromescope:neversion:6.0.472.59

Trust: 0.3

vendor:applemodel:safari for windowsscope:neversion:5.0.4

Trust: 0.3

vendor:applemodel:safariscope:neversion:5.0.4

Trust: 0.3

vendor:applemodel:iosscope:neversion:4.3

Trust: 0.3

sources: ZDI: ZDI-11-095 // BID: 46654 // BID: 46677 // JVNDB: JVNDB-2010-002837 // CNNVD: CNNVD-201009-254 // NVD: CVE-2010-1824

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2010-1824
value: HIGH

Trust: 1.0

NVD: CVE-2010-1824
value: HIGH

Trust: 0.8

ZDI: CVE-2010-1824
value: HIGH

Trust: 0.7

CNNVD: CNNVD-201009-254
value: CRITICAL

Trust: 0.6

VULHUB: VHN-44429
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2010-1824
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

ZDI: CVE-2010-1824
severity: HIGH
baseScore: 9.7
vectorString: AV:N/AC:L/AU:N/C:C/I:P/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: PARTIAL
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 9.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

VULHUB: VHN-44429
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: ZDI: ZDI-11-095 // VULHUB: VHN-44429 // JVNDB: JVNDB-2010-002837 // CNNVD: CNNVD-201009-254 // NVD: CVE-2010-1824

PROBLEMTYPE DATA

problemtype:CWE-416

Trust: 1.1

problemtype:CWE-399

Trust: 0.9

sources: VULHUB: VHN-44429 // JVNDB: JVNDB-2010-002837 // NVD: CVE-2010-1824

THREAT TYPE

remote

Trust: 0.8

sources: PACKETSTORM: 98855 // PACKETSTORM: 104366 // CNNVD: CNNVD-201009-254

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201009-254

CONFIGURATIONS

sources: JVNDB: JVNDB-2010-002837

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-44429

PATCH

title:HT4554url:http://support.apple.com/kb/HT4554

Trust: 1.5

title:HT4564url:http://support.apple.com/kb/HT4564

Trust: 0.8

title:HT4566url:http://support.apple.com/kb/HT4566

Trust: 0.8

title:HT4554url:http://support.apple.com/kb/HT4554?viewlocale=ja_JP

Trust: 0.8

title:HT4564url:http://support.apple.com/kb/HT4564?viewlocale=ja_JP

Trust: 0.8

title:HT4566url:http://support.apple.com/kb/HT4566?viewlocale=ja_JP

Trust: 0.8

title:Google Chromeurl:http://www.google.co.jp/chrome/intl/ja/landing_ff_yt.html?hl=ja&hl=ja

Trust: 0.8

title:stable-beta-channel-updates_14url:http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html

Trust: 0.8

sources: ZDI: ZDI-11-095 // JVNDB: JVNDB-2010-002837

EXTERNAL IDS

db:NVDid:CVE-2010-1824

Trust: 3.7

db:ZDIid:ZDI-11-095

Trust: 2.9

db:SECUNIAid:43068

Trust: 1.8

db:VUPENid:ADV-2011-0212

Trust: 1.7

db:JVNDBid:JVNDB-2010-002837

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-982

Trust: 0.7

db:CNNVDid:CNNVD-201009-254

Trust: 0.7

db:BIDid:46677

Trust: 0.4

db:ZDIid:ZDI-11-098

Trust: 0.4

db:ZDIid:ZDI-11-097

Trust: 0.4

db:ZDIid:ZDI-11-101

Trust: 0.4

db:ZDIid:ZDI-11-096

Trust: 0.4

db:ZDIid:ZDI-11-099

Trust: 0.4

db:ZDIid:ZDI-11-100

Trust: 0.4

db:BIDid:46654

Trust: 0.3

db:PACKETSTORMid:104366

Trust: 0.2

db:PACKETSTORMid:98855

Trust: 0.2

db:SECUNIAid:43582

Trust: 0.2

db:VULHUBid:VHN-44429

Trust: 0.1

db:PACKETSTORMid:98876

Trust: 0.1

db:PACKETSTORMid:97846

Trust: 0.1

sources: ZDI: ZDI-11-095 // VULHUB: VHN-44429 // BID: 46654 // BID: 46677 // JVNDB: JVNDB-2010-002837 // PACKETSTORM: 98876 // PACKETSTORM: 97846 // PACKETSTORM: 98855 // PACKETSTORM: 104366 // CNNVD: CNNVD-201009-254 // NVD: CVE-2010-1824

REFERENCES

url:http://support.apple.com/kb/ht4554

Trust: 2.9

url:http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.html

Trust: 2.0

url:http://www.zerodayinitiative.com/advisories/zdi-11-095

Trust: 1.8

url:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html

Trust: 1.8

url:http://lists.apple.com/archives/security-announce/2011/mar/msg00000.html

Trust: 1.7

url:http://code.google.com/p/chromium/issues/detail?id=50712

Trust: 1.7

url:http://support.apple.com/kb/ht4566

Trust: 1.7

url:https://bugs.webkit.org/show_bug.cgi?id=43260

Trust: 1.7

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a7151

Trust: 1.7

url:http://secunia.com/advisories/43068

Trust: 1.7

url:http://www.vupen.com/english/advisories/2011/0212

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2010-1824

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2010-1824

Trust: 0.8

url:http://www.apple.com/itunes/

Trust: 0.6

url:http://www.webkit.org/

Trust: 0.6

url:http://www.zerodayinitiative.com/advisories/zdi-11-096/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-097/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-098/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-099/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-100/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-101/

Trust: 0.4

url:http://www.zerodayinitiative.com/advisories/zdi-11-095/

Trust: 0.4

url:http://www.google.com/chrome

Trust: 0.3

url:http://secunia.com/products/corporate/evm/

Trust: 0.2

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.2

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.2

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.2

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.2

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2010-1824

Trust: 0.2

url:http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=897

Trust: 0.1

url:http://secunia.com/advisories/43582/

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=43582

Trust: 0.1

url:http://secunia.com/products/corporate/vim/section_179/

Trust: 0.1

url:http://secunia.com/advisories/43582/#comments

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=43068

Trust: 0.1

url:http://secunia.com/products/corporate/vim/

Trust: 0.1

url:http://secunia.com/advisories/43068/#comments

Trust: 0.1

url:http://secunia.com/advisories/43068/

Trust: 0.1

url:http://www.zerodayinitiative.com/advisories/disclosure_policy/

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://twitter.com/thezdi

Trust: 0.1

url:http://www.tippingpoint.com

Trust: 0.1

url:http://www.zerodayinitiative.com

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3812

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4492

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0778

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4042

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2651

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4577

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4197

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.10.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/webkit/1.2.7-0ubuntu0.10.04.1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3254

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3813

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2900

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4204

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4199

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4198

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4493

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2646

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4206

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0482

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2901

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4040

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3120

Trust: 0.1

url:http://www.ubuntu.com/usn/usn-1195-1

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4578

Trust: 0.1

sources: ZDI: ZDI-11-095 // VULHUB: VHN-44429 // BID: 46654 // BID: 46677 // JVNDB: JVNDB-2010-002837 // PACKETSTORM: 98876 // PACKETSTORM: 97846 // PACKETSTORM: 98855 // PACKETSTORM: 104366 // CNNVD: CNNVD-201009-254 // NVD: CVE-2010-1824

CREDITS

wushi of team509

Trust: 1.0

sources: ZDI: ZDI-11-095 // BID: 46677

SOURCES

db:ZDIid:ZDI-11-095
db:VULHUBid:VHN-44429
db:BIDid:46654
db:BIDid:46677
db:JVNDBid:JVNDB-2010-002837
db:PACKETSTORMid:98876
db:PACKETSTORMid:97846
db:PACKETSTORMid:98855
db:PACKETSTORMid:104366
db:CNNVDid:CNNVD-201009-254
db:NVDid:CVE-2010-1824

LAST UPDATE DATE

2024-11-23T20:11:51.419000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-11-095date:2011-03-02T00:00:00
db:VULHUBid:VHN-44429date:2020-07-31T00:00:00
db:BIDid:46654date:2011-03-07T17:27:00
db:BIDid:46677date:2015-03-19T09:40:00
db:JVNDBid:JVNDB-2010-002837date:2011-06-09T00:00:00
db:CNNVDid:CNNVD-201009-254date:2020-08-03T00:00:00
db:NVDid:CVE-2010-1824date:2024-11-21T01:15:16.360

SOURCES RELEASE DATE

db:ZDIid:ZDI-11-095date:2011-03-02T00:00:00
db:VULHUBid:VHN-44429date:2010-09-24T00:00:00
db:BIDid:46654date:2011-03-02T00:00:00
db:BIDid:46677date:2010-09-14T00:00:00
db:JVNDBid:JVNDB-2010-002837date:2011-06-09T00:00:00
db:PACKETSTORMid:98876date:2011-03-03T03:30:18
db:PACKETSTORMid:97846date:2011-01-25T03:59:20
db:PACKETSTORMid:98855date:2011-03-03T15:46:08
db:PACKETSTORMid:104366date:2011-08-23T14:33:53
db:CNNVDid:CNNVD-201009-254date:2010-09-28T00:00:00
db:NVDid:CVE-2010-1824date:2010-09-24T19:00:04.387