CVE-2010-3119
published 2010-08-24CVE-2010-3119: Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service…
PriorityP427critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.42%
70.1th percentile
Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 5.0.375.127 | 5.0.375.127 | |
| webkitgtk | webkitgtk | < 1.2.6 | 1.2.6 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3hjv-5h38-3p2g: Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-3119 [HIGH] CWE-119 GHSA-3hjv-5h38-3p2g: Google Chrome before 5
Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Red Hat
webkit: DoS due to improper Ruby support
vendor_redhat·2010-08-19·CVSS 10.0
CVE-2010-3119 [CRITICAL] webkit: DoS due to improper Ruby support
webkit: DoS due to improper Ruby support
Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id INSERT
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id INSERT"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004643; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Ini
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UPDATE
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UPDATE"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004646; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Init
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UNION SELECT
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id UNION SELECT"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004642; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_ta
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id SELECT
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id SELECT"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004641; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Ini
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id ASCII
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id ASCII"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004645; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Ini
Suricata
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-3119 [HIGH] ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id DELETE
ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Kartli Alisveris Sistemi SQL Injection Attempt -- news.asp news_id DELETE"; flow:established,to_server; http.uri; content:"/news.asp?"; nocase; content:"news_id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-3119; reference:url,www.exploit-db.com/exploits/4040/; classtype:web-application-attack; sid:2004644; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Ini
No public exploits indexed.
Bugzilla
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
bugzilla·2011-01-04·CVSS 10.0
CVE-2010-4198 [CRITICAL] CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4197
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115
---
Adding parent bug CVE-2010-4206
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115,656129
---
Adding parent bug CVE-2010-3812
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-3119 webkit: DoS due to improper Ruby support
bugzilla·2010-08-27·CVSS 10.0
CVE-2010-3119 [CRITICAL] CVE-2010-3119 webkit: DoS due to improper Ruby support
CVE-2010-3119 webkit: DoS due to improper Ruby support
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3119 to
the following vulnerability:
Name: CVE-2010-3119
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3119
Assigned: 20100824
Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=51654
Reference: CONFIRM: http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
Google Chrome before 5.0.375.127 does not properly support the Ruby
language, which allows attackers to cause a denial of service (memory
corruption) or possibly have unspecified other impact via unknown
vectors.
This flaw also affects upstream WebKit:
https://bugs.webkit.org/show_bug.cgi?id=43795
http://trac.webkit.org/changeset/65090
Discussion:
T
http://code.google.com/p/chromium/issues/detail?id=51654http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12107http://code.google.com/p/chromium/issues/detail?id=51654http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12107
2010-08-24
Published