FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-3114

This CVE name corresponds to:

Entered Topic
2010-10-19 Webkit-gtk2 -- Multiple Vulnabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-3114
Phase Assigned(20100824)

Description

The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.

References

Source Reference
CONFIRM http://code.google.com/p/chromium/issues/detail?id=49628
CONFIRM http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
CONFIRM http://trac.webkit.org/changeset/63773
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=628035
MANDRIVA MDVSA-2011:039
REDHAT RHSA-2011:0177
UBUNTU USN-1006-1
BID 44201
OVAL oval:org.mitre.oval:def:11577
SECUNIA 41856
SECUNIA 43086
VUPEN ADV-2010-2722
VUPEN ADV-2011-0216
VUPEN ADV-2011-0552