Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
BID:39804
Info
Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
| Bugtraq ID: | 39804 |
| Class: | Unknown |
| CVE: |
CVE-2010-1664 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2010 12:00AM |
| Updated: | Mar 02 2011 04:18PM |
| Credit: | David Bloom of Google Security Team |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 amd64 MandrakeSoft Linux Mandrake 2010.1 x86_64 MandrakeSoft Linux Mandrake 2010.1 Google Chrome 4.1.249 1059 Google Chrome 4.1.249 1036 Google Chrome 4.1.249 .1045 Google Chrome 4.1.249 .1042 Google Chrome 4.0.249 .89 Google Chrome 4.0.249 .78 |
| Not Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 Google Chrome 4.1.249 1064 |
Discussion
Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
Google Chrome is prone to a memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Succesful exploits will allow attackers to execute arbitrary code in the context of the browser. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Chrome 4.1.249.1064 are vulnerable.
NOTE: This issue was previously covered in 39750 (Google Chrome prior to 4.1.249.1064 Multiple Security Vulnerabilities but has been assigned its own record to better document it.
Google Chrome is prone to a memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Succesful exploits will allow attackers to execute arbitrary code in the context of the browser. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Chrome 4.1.249.1064 are vulnerable.
NOTE: This issue was previously covered in 39750 (Google Chrome prior to 4.1.249.1064 Multiple Security Vulnerabilities but has been assigned its own record to better document it.
Exploit / POC
Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Ubuntu Ubuntu Linux 10.10 amd64
Ubuntu Ubuntu Linux 10.04 powerpc
MandrakeSoft Linux Mandrake 2010.1
Ubuntu Ubuntu Linux 9.10 i386
Ubuntu Ubuntu Linux 10.04 amd64
Ubuntu Ubuntu Linux 10.10 powerpc
Ubuntu Ubuntu Linux 9.10 powerpc
Ubuntu Ubuntu Linux 9.10 amd64
Ubuntu Ubuntu Linux 10.10 i386
Ubuntu Ubuntu Linux 9.10 lpia
MandrakeSoft Linux Mandrake 2010.1 x86_64
Ubuntu Ubuntu Linux 10.04 sparc
Ubuntu Ubuntu Linux 10.04 i386
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.9.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.9.10.1_sparc.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.9.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.9.10.1_sparc.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.9.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.9.10.1_all.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.9.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.9.10.1_sparc.deb
Ubuntu Ubuntu Linux 10.10 amd64
-
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/w/webkit/gir1.0-webkit -1.0_1.2.5-0ubuntu0.10.10.1_amd64.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.10.10.1_amd64.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.10.10.1_amd64.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.10.10.1_amd64.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.10.1_all.deb
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.04.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.04.1_all.deb -
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.04.1_powerpc.deb
http://ports.ubuntu.com/pool/universe/w/webkit/gir1.0-webkit-1.0_1.2.5 -0ubuntu0.10.04.1_powerpc.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.04.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.10.04.1_powerpc.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.04.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.10.04.1_powerpc.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.04.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.10.04.1_powerpc.deb
MandrakeSoft Linux Mandrake 2010.1
-
Mandriva webkit1.0-webinspector-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-jsc-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwebkitgtk1.0-devel-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit1.0-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva libwebkitgtk1.0_2-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-gtklauncher-1.2.7-0.1mdv2010.2.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.9.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.9.10.1_i386.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.9.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.9.10.1_i386.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.9.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.9.10.1_i386.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.9.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.9.10.1_all.deb
Ubuntu Ubuntu Linux 10.04 amd64
-
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/universe/w/webkit/gir1.0-webkit -1.0_1.2.5-0ubuntu0.10.04.1_amd64.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.10.04.1_amd64.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.10.04.1_amd64.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.10.04.1_amd64.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.04.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.04.1_all.deb
Ubuntu Ubuntu Linux 10.10 powerpc
-
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.10.1_powerpc.deb
http://ports.ubuntu.com/pool/universe/w/webkit/gir1.0-webkit-1.0_1.2.5 -0ubuntu0.10.10.1_powerpc.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.10.10.1_powerpc.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.10.10.1_powerpc.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.10.10.1_powerpc.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.10.1_all.deb
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.9.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.9.10.1_powerpc.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.9.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.9.10.1_powerpc.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.9.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.9.10.1_powerpc.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.9.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.9.10.1_all.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.9.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.9.10.1_amd64.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.9.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.9.10.1_amd64.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.9.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.9.10.1_all.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.9.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.9.10.1_amd64.deb
Ubuntu Ubuntu Linux 10.10 i386
-
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.10.10.1_i386.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.10.10.1_i386.deb -
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/w/webkit/gir1.0-webkit -1.0_1.2.5-0ubuntu0.10.10.1_i386.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.10.10.1_i386.deb -
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.10.1_all.deb
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.9.10.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.9.10.1_all.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.9.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.9.10.1_lpia.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.9.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.9.10.1_lpia.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.9.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.9.10.1_lpia.deb
MandrakeSoft Linux Mandrake 2010.1 x86_64
-
Mandriva lib64webkitgtk1.0-devel-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-jsc-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-gtklauncher-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit1.0-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva lib64webkitgtk1.0_2-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/ -
Mandriva webkit1.0-webinspector-1.2.7-0.1mdv2010.2.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 10.04 sparc
-
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.04.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.04.1_all.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.04.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2_1.2.5-0ubun tu0.10.04.1_sparc.deb -
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.04.1_sparc.deb
http://ports.ubuntu.com/pool/universe/w/webkit/gir1.0-webkit-1.0_1.2.5 -0ubuntu0.10.04.1_sparc.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.04.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-dev_1.2.5-0ubuntu 0.10.04.1_sparc.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.04.1_sparc.deb
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-2-dbg_1.2.5-0 ubuntu0.10.04.1_sparc.deb
Ubuntu Ubuntu Linux 10.04 i386
-
Ubuntu libwebkit-1.0-common_1.2.5-0ubuntu0.10.04.1_all.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-com mon_1.2.5-0ubuntu0.10.04.1_all.deb -
Ubuntu libwebkit-1.0-2-dbg_1.2.5-0ubuntu0.10.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2-d bg_1.2.5-0ubuntu0.10.04.1_i386.deb -
Ubuntu libwebkit-dev_1.2.5-0ubuntu0.10.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.2 .5-0ubuntu0.10.04.1_i386.deb -
Ubuntu gir1.0-webkit-1.0_1.2.5-0ubuntu0.10.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/universe/w/webkit/gir1.0-webkit -1.0_1.2.5-0ubuntu0.10.04.1_i386.deb -
Ubuntu libwebkit-1.0-2_1.2.5-0ubuntu0.10.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-2_1 .2.5-0ubuntu0.10.04.1_i386.deb
References
Google Chrome HTML5 Media Handling Memory Corruption Vulnerability
References:
References:
- Google Chrome 4.1.249.1064 has been released to the Stable channel on Windows (Google)
- Google Chrome Homepage (Google)
- webkit 1.2.5 security update tracking bug (Ubuntu)
- Webkit Homepage (Webkit)