CVE-2010-1773
published 2010-09-24CVE-2010-1773: Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70…
PriorityP336high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.15%
80.1th percentile
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 5.0.375.70 | 5.0.375.70 | |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
vendor_redhat·2010-06-07·CVSS 8.8
CVE-2010-1773 [HIGH] CWE-193 WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
Package: qt (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
Red Hat
webkitgtk: Memory corruption by rendering the list item's marker
vendor_redhat·2010-05-24·CVSS 8.8
CVE-2010-2304 [HIGH] webkitgtk: Memory corruption by rendering the list item's marker
webkitgtk: Memory corruption by rendering the list item's marker
No description is available for this CVE.
Statement: This is a duplicate of CVE-2010-1773. CVE-2010-2304 was assigned against WebKit as present in Google Chrome, however CVE-2010-1773 was previously assigned to upstream WebKit. They are the same issue, however, as noted by the same upstream webkit bug ID (#39508).
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-rg88-8376-6jqq: Off-by-one error in the toAlphabetic function in rendering/RenderListMarker
ghsa_unreviewed·2022-05-13
CVE-2010-1773 [HIGH] CWE-193 GHSA-rg88-8376-6jqq: Off-by-one error in the toAlphabetic function in rendering/RenderListMarker
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
No detection rules found.
No public exploits indexed.
Bugzilla
Please update to webkitgtk-1.2.3
bugzilla·2010-07-18·CVSS 10.0
[CRITICAL] Please update to webkitgtk-1.2.3
Please update to webkitgtk-1.2.3
Description of problem:
New version in the stable series of webkitgtk is available.
Version-Release number of selected component (if applicable):
webkitgtk-1.2.0-1.fc12.i686
From the announcement [1]:
"Some of you may have noticed WebKitGTK+ 1.2.2 and 1.2.3 have been uploaded recently. Here’s their announcement =). A quick summary: if you’re running the 1.2.x series upgrade to 1.2.3."
According the announcement It should fix one annoying bug with dragging current build is affected with.
It also includes fixes to various CVEs some of which might be also present in current fedora release. Full list of them is in NEWS file [2].
According to the NEWS it also is API/ABI compatible with current fedora release, so no incompatibility problems should arise fro
Bugzilla
update webkitgtk to 1.2.3
bugzilla·2010-07-16·CVSS 10.0
[CRITICAL] update webkitgtk to 1.2.3
update webkitgtk to 1.2.3
Description of problem:
A new version has been released by upstream so we may rebase to it. See http://www.webkitgtk.org/?page=download
Discussion:
From the NEWS file:
What's new in WebKitGTK+ 1.2.3?
- New stable release, API and ABI compatible with previous 1.2.x
versions;
- Includes a fix to build WebKit with ICU 4.4.1
- The patches to fix the following CVEs are included, thanks to the
work done by Michael Gilbert for the
Debian security team:
CVE-2010-1386 CVE-2010-1392 CVE-2010-1405 CVE-2010-1407
CVE-2010-1416 CVE-2010-1417 CVE-2010-1665 CVE-2010-1418
CVE-2010-1421 CVE-2010-1422 CVE-2010-1501 CVE-2010-1767
CVE-2010-1664 CVE-2010-1758 CVE-2010-1759 CVE-2010-1760
CVE-2010-1761 CVE-2010-1762 CVE-2010-1770 CVE-2010-1771
CVE-2010-1772 CVE-2010-1773 CVE-2010-
Bugzilla
CVE-2010-2304 webkitgtk: Memory corruption by rendering the list item's marker
bugzilla·2010-06-21·CVSS 8.8
CVE-2010-2304 [HIGH] CVE-2010-2304 webkitgtk: Memory corruption by rendering the list item's marker
CVE-2010-2304 webkitgtk: Memory corruption by rendering the list item's marker
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-2304 to
the following vulnerability:
The toAlphabetic function in rendering/RenderListMarker.cpp in WebCore
in WebKit in Google Chrome before 5.0.375.70 allows remote attackers
to cause a denial of service (memory corruption) or possibly execute
arbitrary code via vectors related to list markers, aka rdar problem
8009118.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2304
[2] http://code.google.com/p/chromium/issues/detail?id=44955
[3] http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html
[4] http://secunia.com/advisories/40072
Upstream changeset:
[5] http://trac.webkit.org/changeset/59950
Ups
Bugzilla
CVE-2010-1773 webkitgtk: Memory corruption by rendering the list item's marker [fedora-12]
bugzilla·2010-06-21·CVSS 8.8
CVE-2010-1773 [HIGH] CVE-2010-1773 webkitgtk: Memory corruption by rendering the list item's marker [fedora-12]
CVE-2010-1773 webkitgtk: Memory corruption by rendering the list item's marker [fedora-12]
fedora-12 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
webkitgtk-1.2.4-1.fc13 has been submitted as an update for Fedora 13.
https://admin.fedoraproject.org/updates/webkitgtk-1.2.4-1.fc13
---
webkitgtk-1.2.4-1.fc12 has been submitted as an update for Fedora 12.
https://admin.fedoraproject.org/updates/webkitgtk-1.2.4-1.fc12
---
webkitgtk-1.2.4-1.fc13 has been pushed to the Fedora 13 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test
Bugzilla
CVE-2010-1772 CVE-2010-1773 webkitgtk various flaws [fedora-all]
bugzilla·2010-06-21·CVSS 7.5
CVE-2010-1772 [HIGH] CVE-2010-1772 CVE-2010-1773 webkitgtk various flaws [fedora-all]
CVE-2010-1772 CVE-2010-1773 webkitgtk various flaws [fedora-all]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-1766
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=606295,596494
---
Adding parent bug CVE-2010-1772
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=606295,596494,596498
---
Adding parent bug CVE-2010-1773
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=606295,596494,596498,596500
---
Removing CVE-2010-1766 from the
Bugzilla
CVE-2010-1773 WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
bugzilla·2010-05-26·CVSS 8.8
CVE-2010-1773 [HIGH] CVE-2010-1773 WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
CVE-2010-1773 WebKit: off-by-one memory read out of bounds vulnerability in handling of HTML lists
An off by one memory read out of bounds issue exists in WebKit's handling of HTML lists. Visiting a maliciously crafted website may lead to an unexpected application termination or the disclosure of the contents of memory. This issue is addressed through improved bounds checking.
References:
Bugzilla: https://bugs.webkit.org/show_bug.cgi?id=39508
Trac: http://trac.webkit.org/changeset/59950
Acknowledgements:
Red Hat would like to thank Drew Yao of Apple Product Security for responsibly reporting this issue.
Discussion:
This is being made public now, we've been given the go-ahead from upstream to do so.
---
Created webkitgtk tracking bugs for this issue
Affects: fedora-all [bug 60630
http://code.google.com/p/chromium/issues/detail?id=44955http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40072http://secunia.com/advisories/40557http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://trac.webkit.org/changeset/59950http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/41575http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1801http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=39508https://bugzilla.redhat.com/show_bug.cgi?id=596500https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11830http://code.google.com/p/chromium/issues/detail?id=44955http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40072http://secunia.com/advisories/40557http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://trac.webkit.org/changeset/59950http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/bid/41575http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1801http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=39508https://bugzilla.redhat.com/show_bug.cgi?id=596500https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11830
2010-09-24
Published