PublicDate: 2008-06-23 20:41:00 UTC Candidate: CVE-2008-2307 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2307 Description: Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption. Ubuntu-Description: Notes: mdeslaur> qt4-x11 doesn't look vulnerable (code is different) Bugs: Priority: medium Discovered-by: Assigned-to: micahg CVSS: Patches_webkit: upstream: http://trac.webkit.org/changeset/34204 upstream_webkit: needs-triage dapper_webkit: DNE feisty_webkit: DNE gutsy_webkit: needs-triage (reached end-of-life) hardy_webkit: ignored (reached end-of-life) intrepid_webkit: not-affected (1.0.1-2) jaunty_webkit: not-affected (1.0.1-4) karmic_webkit: not-affected (1.0.1-4) lucid_webkit: not-affected (1.0.1-4) maverick_webkit: not-affected (1.0.1-4) natty_webkit: not-affected (1.0.1-4) devel_webkit: not-affected (1.0.1-4)