CVE-2011-3064
published 2012-03-30CVE-2011-3064: Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.15%
80.2th percentile
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 6.0 | 6.0 |
| apple | itunes | < 10.7 | 10.7 |
| apple | safari | < 6.0 | 6.0 |
| chrome | < 18.0.1025.142 | 18.0.1025.142 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2012-10-25
CVE-2011-3059 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
WebkitGtk: Use-after-free in SVG clipping.
vendor_redhat·2012-03-28·CVSS 7.5
CVE-2011-3064 [HIGH] CWE-416 WebkitGtk: Use-after-free in SVG clipping.
WebkitGtk: Use-after-free in SVG clipping.
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
Statement: This issue affects the version of webkitgtk as shipped with Red Hat Enterprise Linux 6.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-fc76-wjg5-5742: Use-after-free vulnerability in Google Chrome before 18
ghsa_unreviewed·2022-05-13
CVE-2011-3064 [HIGH] CWE-416 GHSA-fc76-wjg5-5742: Use-after-free vulnerability in Google Chrome before 18
Use-after-free vulnerability in Google Chrome before 18.0.1025.142 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG clipping.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping. [fedora-all]
bugzilla·2012-03-29·CVSS 7.5
CVE-2011-3064 [HIGH] CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping. [fedora-all]
CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=
Bugzilla
CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping.
bugzilla·2012-03-28·CVSS 7.5
CVE-2011-3064 [HIGH] CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping.
CVE-2011-3064 WebkitGtk: Use-after-free in SVG clipping.
A use-after-free flaw was found in the way SVG clipping was implemented in Webkit.
Reference:
https://bugs.webkit.org/show_bug.cgi?id=80669
http://code.google.com/p/chromium/issues/detail?id=117471
Patch: http://trac.webkit.org/changeset/110563
Statement:
This issue affects the version of webkitgtk as shipped with Red Hat Enterprise Linux 6.
Discussion:
Created webkitgtk tracking bugs for this issue
Affects: fedora-all [bug 807891]
http://code.google.com/p/chromium/issues/detail?id=117471http://googlechromereleases.blogspot.com/2012/03/stable-channel-release-and-beta-channel.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://osvdb.org/80742http://secunia.com/advisories/48618http://secunia.com/advisories/48691http://secunia.com/advisories/48763http://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52762http://www.securitytracker.com/id?1026877https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14755http://code.google.com/p/chromium/issues/detail?id=117471http://googlechromereleases.blogspot.com/2012/03/stable-channel-release-and-beta-channel.htmlhttp://lists.apple.com/archives/security-announce/2012/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Sep/msg00003.htmlhttp://osvdb.org/80742http://secunia.com/advisories/48618http://secunia.com/advisories/48691http://secunia.com/advisories/48763http://support.apple.com/kb/HT5400http://support.apple.com/kb/HT5485http://support.apple.com/kb/HT5503http://www.securityfocus.com/bid/52762http://www.securitytracker.com/id?1026877https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14755
2012-03-30
Published