Candidate: CVE-2010-1405 PublicDate: 2010-06-11 18:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1405 https://ubuntu.com/security/notices/USN-1006-1 Description: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning. Ubuntu-Description: Notes: jdstrand> qt4-x11 unmaintained upstream (see README.webkit for details) jdstrand> webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit. mdeslaur> webkitkde is a wrapper around qt4-x11's webkit. Bugs: https://bugs.webkit.org/show_bug.cgi?id=36198 Priority: low Discovered-by: Assigned-to: micahg CVSS: Patches_webkit: upstream: http://trac.webkit.org/changeset/56186 upstream_webkit: released (1.2.3) dapper_webkit: DNE hardy_webkit: ignored (reached end-of-life) jaunty_webkit: ignored (reached end-of-life) karmic_webkit: released (1.2.5-0ubuntu0.9.10.1) lucid_webkit: released (1.2.5-0ubuntu0.10.04.1) maverick_webkit: not-affected (1.2.4-1ubuntu1) natty_webkit: not-affected (1.2.4-1ubuntu1) oneiric_webkit: not-affected (1.2.4-1ubuntu1) devel_webkit: not-affected (1.2.4-1ubuntu1) Patches_qt4-x11: upstream_qt4-x11: needs-triage dapper_qt4-x11: not-affected (no webkit) hardy_qt4-x11: not-affected (no webkit) jaunty_qt4-x11: ignored (reached end-of-life) karmic_qt4-x11: ignored (reached end-of-life) lucid_qt4-x11: ignored (see notes) maverick_qt4-x11: not-affected (webkit isn't built) natty_qt4-x11: not-affected (webkit isn't built) oneiric_qt4-x11: not-affected (webkit isn't built) devel_qt4-x11: not-affected (webkit isn't built) Patches_chromium-browser: upstream_chromium-browser: needs-triage dapper_chromium-browser: DNE hardy_chromium-browser: DNE jaunty_chromium-browser: DNE karmic_chromium-browser: DNE lucid_chromium-browser: ignored (uses its own embedded webkit) maverick_chromium-browser: ignored (uses its own embedded webkit) natty_chromium-browser: ignored (uses its own embedded webkit) oneiric_chromium-browser: ignored (uses its own embedded webkit) devel_chromium-browser: ignored (uses its own embedded webkit)