HIGH
WebKit: off-by-one memory corruption flaw WebSocketHandshake::readServerHandshake()
Published Jul 22, 2010
7.5
HIGHCVSS 2.0
EPSS 2.25%
Description
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.
Affected products
No data.
No data.
Red Hat Enterprise Linux 6
qt
Will not fix
Red Hat Enterprise Linux 6
webkitgtk
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | qt | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | webkitgtk | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (18)
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html vendor-advisoryx_refsource_FEDORA
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html vendor-advisoryx_refsource_FEDORA
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/40557 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/41856 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://trac.webkit.org/changeset/56380 x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 vendor-advisoryx_refsource_MANDRIVA
- http://www.ubuntu.com/usn/USN-1006-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2010/1801 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2010/2722 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0552 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2010-1766 Vendor Advisory
- https://bugs.webkit.org/show_bug.cgi?id=36339 x_refsource_CONFIRM
- https://bugzilla.redhat.com/show_bug.cgi?id=596494 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2010-1766
- https://www.cve.org/CVERecord?id=CVE-2010-1766
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Jul 22, 2010
Updated Aug 7, 2024
Reserved May 6, 2010
Link CVE-2010-1766
CISA Vulnrichment
Updated n/a