WebKit 'foreignObject' Elements Use-After-Free Remote Code Execution Vulnerability
BID:42046
Info
WebKit 'foreignObject' Elements Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 42046 |
| Class: | Unknown |
| CVE: |
CVE-2010-1786 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2010 12:00AM |
| Updated: | Apr 13 2015 09:27PM |
| Credit: | wushi of team509, working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 amd64 S.u.S.E. openSUSE 11.3 S.u.S.E. openSUSE 11.2 Redhat Enterprise Linux Workstation Optional 6 Redhat Enterprise Linux Workstation 6 Redhat Enterprise Linux Server Optional 6 Redhat Enterprise Linux Server 6 Redhat Enterprise Linux HPC Node Optional 6 Redhat Enterprise Linux Desktop Optional 6 Redhat Enterprise Linux Desktop 6 Mandriva Linux Mandrake 2010.1 x86_64 Mandriva Linux Mandrake 2010.1 Gentoo Linux Apple Safari 4.0.5 for Windows Apple Safari 4.0.5 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Safari 4.1 Apple Safari 4 for Windows Apple Safari 4 Beta Apple Safari 4 Apple iTunes 9.0.2 Apple iTunes 9.0.1 .8 Apple iTunes 9.0.1 Apple iTunes 9.0 Apple iTunes 9.2 Apple iTunes 9.1 Apple iPod Touch 3.1.3 Apple iPod Touch 3.1.2 Apple iPod Touch 3.1.1 Apple iPod Touch 2.2.1 Apple iPod Touch 2.0.2 Apple iPod Touch 2.0.1 Apple iPod Touch 3.0 Apple iPod Touch 2.2 Apple iPod Touch 2.1 Apple iPod Touch 2.0 Apple iPhone 4.0.1 Apple iPhone 3.2.1 Apple iPhone 3.1.3 Apple iPhone 3.1.2 Apple iPhone 3.0.1 Apple iPhone 2.2.1 Apple iPhone 2.0.2 Apple iPhone 2.0.1 Apple iPhone 4.0 Apple iPhone 3.2 Apple iPhone 3.1 Apple iPhone 3.0 Apple iPhone 2.2 Apple iPhone 2.1 Apple iPhone 2.0 Apple iPad 3.2.1 Apple iPad 3.2.2 Apple iPad 3.2 Apple iPad 0 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.2 beta Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 2.0 |
| Not Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 Apple Safari 5.0.1 Apple Safari 4.1.1 Apple iTunes 10 Apple iOS 4.2 Apple iOS 4.1 |
Discussion
WebKit 'foreignObject' Elements Use-After-Free Remote Code Execution Vulnerability
WebKit is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a web page containing malicious content. A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the user running the affected application.
This issue has been addressed in Apple Safari 5.0.1 and 4.1.1.
NOTE: This issue was previously covered in BID 42020 (Apple Safari Prior to 5.0.1 and 4.1.1 Multiple Security Vulnerabilities) but has been given its own record to better document it.
WebKit is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a web page containing malicious content. A successful exploit will result in the execution of arbitrary attacker-supplied code in the context of the user running the affected application.
This issue has been addressed in Apple Safari 5.0.1 and 4.1.1.
NOTE: This issue was previously covered in BID 42020 (Apple Safari Prior to 5.0.1 and 4.1.1 Multiple Security Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
WebKit 'foreignObject' Elements Use-After-Free Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].