Candidate: CVE-2010-3115 PublicDate: 2010-08-24 20:00:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3115 https://ubuntu.com/security/notices/USN-1006-1 Description: Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: micahg CVSS: Patches_webkit: upstream: http://trac.webkit.org/changeset/63925 upstream: http://trac.webkit.org/changeset/64077 upstream_webkit: released (1.2.5) dapper_webkit: DNE hardy_webkit: ignored (reached end-of-life) jaunty_webkit: ignored (reached end-of-life) karmic_webkit: released (1.2.5-0ubuntu0.9.10.1) lucid_webkit: released (1.2.5-0ubuntu0.10.04.1) maverick_webkit: released (1.2.5-0ubuntu0.10.10.1) natty_webkit: not-affected (1.2.5-0ubuntu2) devel_webkit: not-affected (1.2.5-0ubuntu2) Patches_chromium-browser: upstream_chromium-browser: released (5.0.375.127) dapper_chromium-browser: DNE hardy_chromium-browser: DNE jaunty_chromium-browser: DNE karmic_chromium-browser: DNE lucid_chromium-browser: released (6.0.472.53~r57914-0ubuntu0.10.04.1) maverick_chromium-browser: not-affected natty_chromium-browser: not-affected devel_chromium-browser: not-affected