Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-1690
HistoryJun 10, 2009 - 12:00 a.m.

CVE-2009-1690

2009-06-1000:00:00
ubuntu.com
ubuntu.com
15

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.053 Low

EPSS

Percentile

93.1%

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0,
iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1,
Google Chrome 1.0.154.53, and possibly other products, allows remote
attackers to execute arbitrary code or cause a denial of service (memory
corruption and application crash) by setting an unspecified property of an
HTML tag that causes child elements to be freed and later accessed when an
HTML error occurs, related to “recursion in certain DOM event handlers.”

Bugs

Notes

Author Note
jdstrand webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit
mdeslaur PoC: http://trac.webkit.org/browser/trunk/LayoutTests/fast/parser/head-content-after-head-removal.html?format=txt (need to add the <html> tags)
OSVersionArchitecturePackageVersionFilename
ubuntu8.10noarchkde4libs< 4:4.1.4-0ubuntu1~intrepid1.2UNKNOWN
ubuntu9.04noarchkde4libs< 4:4.2.2-0ubuntu5.1UNKNOWN
ubuntu8.04noarchkdelibs< 4:3.5.10-0ubuntu1~hardy1.2UNKNOWN
ubuntu8.10noarchkdelibs< 4:3.5.10-0ubuntu6.1UNKNOWN
ubuntu9.04noarchkdelibs< 4:3.5.10.dfsg.1-1ubuntu8.1UNKNOWN
ubuntu9.10noarchkdelibs< 4:3.5.10.dfsg.1-2ubuntu5UNKNOWN
ubuntu10.04noarchkdelibs< 4:3.5.10.dfsg.1-2ubuntu5UNKNOWN
ubuntu10.10noarchkdelibs< 4:3.5.10.dfsg.1-2ubuntu5UNKNOWN
ubuntu11.04noarchkdelibs< 4:3.5.10.dfsg.1-2ubuntu5UNKNOWN
ubuntu8.10noarchqt4-x11< 4.4.3-0ubuntu1.4UNKNOWN
Rows per page:
1-10 of 131

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.053 Low

EPSS

Percentile

93.1%