CVE-2010-1805

Publication date 10 September 2010

Last updated 24 July 2024


Ubuntu priority

Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
qt4-x11 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected
webkit 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper Not in release

Notes


jdstrand

webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit.


mdeslaur

webkitkde is a wrapper around qt4-x11’s webkit.


sbeattie

debian claims this is the DLL path attack