This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
HTTP:STC:CHROME:WEBKIT-OO
|
Severity |
Major
|
Recommended |
No
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
Apple Safari and Google Chrome Webkit Object Outline Memory Corruption
|
Release Date |
2010/12/30
|
Update Number |
1842
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
HTTP: Apple Safari and Google Chrome Webkit Object Outline Memory Corruption
This signature detects attempts to exploit a known memory corruption vulnerability in Webkit, the HTML rendering engine used in Apple's Safari and Google's Chrome Web browser. It is due to memory corruption during the rendering of HTML object outlines. This can be exploited by enticing a user to open a specially crafted Web page. A successful attack can result in memory corruption which can crash the browser or could lead to arbitrary code execution.
Extended Description
Webkit is prone to a memory-corruption vulnerability.
An attacker can exploit this issue by tricking an unsuspecting victim into viewing a web page containing malicious content. Successfully exploiting these issues may allow attackers to crash the affected application or execute arbitrary code.
This issue affects the following:
iOS 2.0 through 4.0.2 for iPhone 3G and later
iOS 2.1 through 4.0.2 for iPod touch (2nd generation) and later
Versions prior to Apple Safari 4.1.2 and 5.0.2
Versions prior to Google Chrome 5.0.375.125
NOTE: This issue was previously discussed in BID 43070 (Apple iPhone/iPod touch Prior to iOS 4.1 Multiple Vulnerabilities) but has been given its own record to better document it.
Affected Products
- Apple ios 2.0
- Apple ios 3.2
- Apple ios 3.2.1
- Apple ios 3.2.2
- Apple ios 4
- Apple ios 4.0.1
- Apple ios 4.0.2
- Apple ios 4.2 beta
- Apple ipad 3.2
- Apple ipad 3.2.1
- Apple ipad 3.2.2
- Apple ipad
- Apple ipad
- Apple iphone 2.0
- Apple iphone 2.0.1
- Apple iphone 2.0.2
- Apple iphone 2.1
- Apple iphone 2.1 - Iphone
- Apple iphone 2.1 - Ipodtouch
- Apple iphone 2.2
- Apple iphone 2.2.1
- Apple iphone 2.2.1 - Iphone
- Apple iphone 2.2.1 - Ipodtouch
- Apple iphone 2.2 - Iphone
- Apple iphone 2.2 - Ipodtouch
- Apple iphone 3.0
- Apple iphone 3.0.1
- Apple iphone 3.0.1 - Iphone
- Apple iphone 3.0.1 - Ipodtouch
- Apple iphone 3.0 - Iphone
- Apple iphone 3.0 - Ipodtouch
- Apple iphone 3.1
- Apple iphone 3.1.2
- Apple iphone 3.1.2 - Iphone
- Apple iphone 3.1.2 - Ipodtouch
- Apple iphone 3.1.3
- Apple iphone 3.1.3 - Iphone
- Apple iphone 3.1.3 - Ipodtouch
- Apple iphone 3.1 - Iphone
- Apple iphone 3.1 - Ipodtouch
- Apple iphone 3.2
- Apple iphone 3.2.1
- Apple iphone 3.2.1 - Ipad
- Apple iphone 3.2 - Iphone
- Apple iphone 3.2 - Ipodtouch
- Apple iphone 4.0
- Apple iphone 4.0.1
- Apple iphone 4.0.1 - Iphone
- Apple iphone 4.0 - Iphone
- Apple iphone 4.0 - Ipodtouch
- Apple ipod_touch 2.0
- Apple ipod_touch 2.0.1
- Apple ipod_touch 2.0.2
- Apple ipod_touch 2.1
- Apple ipod_touch 2.2
- Apple ipod_touch 2.2.1
- Apple ipod_touch 3.0
- Apple ipod_touch 3.1.1
- Apple ipod_touch 3.1.2
- Apple ipod_touch 3.1.3
- Apple safari 4
- Apple safari 4.0.1
- Apple safari 4.0.2
- Apple safari 4.0.2 For Windows
- Apple safari 4.0.3
- Apple safari 4.0.3 For Windows
- Apple safari 4.0.4
- Apple safari 4.0.4 For Windows
- Apple safari 4.0.5
- Apple safari 4.0.5 For Windows
- Apple safari 4.1
- Apple safari 4.1.1
- Apple safari 4.1.2 for Windows
- Apple safari 4 Beta
- Apple safari 4 For Windows
- Apple safari 5.0
- Apple safari 5.0.1
- Apple safari 5.0.1 for Windows
- Apple safari 5.0.2 for Windows
- Apple safari 5.0 For Windows
- Google chrome 5.0.375.0
- Google chrome 5.0.375.1
- Google chrome 5.0.375.10
- Google chrome 5.0.375.11
- Google chrome 5.0.375.12
References