CVE-2010-4577
Summary
| CVE | CVE-2010-4577 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-12-22 01:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion." |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-125 | CWE-843 | n/a | CWE-125 CWE-125 Out-of-bounds Read | CWE-843 CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 13 | All | All | All |
| Application | Chrome | All | All | All | All | |
| Operating System | Chrome Os | All | All | All | All | |
| Application | Webkitgtk | Webkitgtk | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 13 Update: webkitgtk-1.2.6-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link, Third Party Advisory |
| Changeset 72685 for trunk/WebCore/css/CSSParser.cpp – WebKit | af854a3a-2127-422b-91ae-364da2661108 | trac.webkit.org | Mailing List, Patch |
| 667025 – (CVE-2010-4577) CVE-2010-4577 webkit: CSS Font Face Parsing Type Confusion Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| WebKit CSS Token Sequences Handling Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Changeset 72685 – WebKit | af854a3a-2127-422b-91ae-364da2661108 | trac.webkit.org | Mailing List, Patch |
| Access Denied | af854a3a-2127-422b-91ae-364da2661108 | bugs.webkit.org | Permissions Required |
| Google Chrome Releases: Stable, Beta Channel Updates | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Release Notes |
| 63866 - chromium - An open-source project to help move the web forward. - Monorail | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | Exploit, Issue Tracking, Mailing List |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link, Third Party Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Broken Link, Third Party Advisory |
| Debian -- Security Information -- DSA-2188-1 webkit | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Third Party Advisory |
| Gentoo Linux Documentation -- Chromium: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Third Party Advisory |
| Red Hat update for webkitgtk - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| Gentoo update for chromium - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.