HIGH
webkit: remote arbitrary code execution via malformed RUBY element
Published Feb 18, 2010
9.3
HIGHCVSS 2.0
EPSS 3.88%
Description
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a <ruby>><table><rt> sequence.
Affected products
No data.
AND
OR
- ≤ 4.0.249.78
- 0.2.149.27
- 0.2.149.29
- 0.2.149.30
- 0.2.152.1
- 0.2.153.1
- 0.3.154.0
- 0.3.154.3
- 0.4.154.18
- 0.4.154.22
- 0.4.154.31
- 0.4.154.33
- 1.0.154.36
- 1.0.154.39
- 1.0.154.42
- 1.0.154.43
- 1.0.154.46
- 1.0.154.48
- 1.0.154.52
- 1.0.154.53
- 1.0.154.59
- 1.0.154.65
- 2.0.156.1
- 2.0.157.0
- 2.0.157.2
- 2.0.158.0
- 2.0.159.0
- 2.0.169.0
- 2.0.169.1
- 2.0.170.0
- 2.0.172
- 2.0.172.2
- 2.0.172.8
- 2.0.172.27
- 2.0.172.28
- 2.0.172.30
- 2.0.172.31
- 2.0.172.33
- 2.0.172.37
- 2.0.172.38
- 3.0.182.2
- 3.0.190.2
- 3.0.193.2
- 3.0.195.21
- 3.0.195.24
- 3.0.195.32
- 3.0.195.33
- 4.0.244.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (24)
- http://code.google.com/p/chromium/issues/detail?id=31692 x_refsource_CONFIRM
- http://googlechromereleases.blogspot.com/2010/02/stable-channel-update.html x_refsource_CONFIRMPatch
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/38545 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41856 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1023583 vdb-entryx_refsource_SECTRACK
- http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs x_refsource_CONFIRMVendor Advisory
- http://trac.webkit.org/changeset/53525 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/62317 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/38177 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-1006-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/0361 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2722 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0552 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-0647 Vendor Advisory
- https://bugs.webkit.org/show_bug.cgi?id=33266 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=568175 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56214 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2010-0647
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14094 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-0647
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 18, 2010
Updated Aug 7, 2024
Reserved Feb 18, 2010
Link CVE-2010-0647
CISA Vulnrichment
Updated n/a