CVE-2010-1029 Information

Description

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit as used in Apple Safari 4.0.4 Apple Safari on iPhone OS and iPhone OS for iPod touch and Google Chrome 4.0.249 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of * sequences.

Reference

http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html http://secunia.com/advisories/43068 http://www.exploit-db.com/exploits/11567 http://www.exploit-db.com/exploits/11574 http://www.securityfocus.com/bid/38398 http://www.vupen.com/english/advisories/2011/0212 https://exchange.xforce.ibmcloud.com/vulnerabilities/56524 https://exchange.xforce.ibmcloud.com/vulnerabilities/56527 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A14301

Share on: