Vulnerability Name: | CVE-2010-0049 (CCN-56835) | ||||||||||||
Assigned: | 2009-12-15 | ||||||||||||
Published: | 2010-03-11 | ||||||||||||
Updated: | 2017-09-19 | ||||||||||||
Summary: | Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality. Per: http://lists.apple.com/archives/security-announce/2010/Mar/msg00000. CVE-ID: CVE-2010-0049 Available for: Mac OS X v10.4.11, Mac OS X Server v10.4.11, Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6.1 or later, Mac OS X Server v10.6.1 or later, Windows 7, Vista, XP Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: A use-after-free issue exists in the handling of HTML elements containing right-to-left displayed text. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved memory reference tracking. Credit to wushi&Z of team509 for reporting this issue. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-0049 Source: IDEFENSE Type: UNKNOWN 20100311 Multiple Vendor WebKit HTML Element Use After Free Vulnerability Source: APPLE Type: UNKNOWN APPLE-SA-2010-06-21-1 Source: APPLE Type: Vendor Advisory APPLE-SA-2010-03-11-1 Source: FEDORA Type: UNKNOWN FEDORA-2010-8360 Source: FEDORA Type: UNKNOWN FEDORA-2010-8379 Source: FEDORA Type: UNKNOWN FEDORA-2010-8423 Source: SUSE Type: UNKNOWN SUSE-SR:2011:002 Source: OSVDB Type: UNKNOWN 62942 Source: CCN Type: SA38932 Apple Safari Multiple Vulnerabilities Source: CCN Type: SA39091 Qt WebKit Multiple Vulnerabilities Source: CCN Type: SA40257 Apple iOS Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 41856 Source: SECUNIA Type: UNKNOWN 43068 Source: CCN Type: SECTRACK ID: 1023708 Apple Safari WebKit Flaws Let Remote Users Execute Arbitrary Code Source: CCN Type: Apple Web site About the security content of Safari 4.0.5 Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT4070 Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT4225 Source: MANDRIVA Type: UNKNOWN MDVSA-2011:039 Source: CCN Type: OSVDB ID: 62942 Apple Safari WebKit HTML Element RTL Text Directionality Use-after-free Arbitrary Code Execution Source: BID Type: Patch 38671 Source: CCN Type: BID-38671 RETIRED: Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities Source: CCN Type: BID-38689 WebKit Right-to-Left Displayed Text Handling Memory Corruption Vulnerability Source: SECTRACK Type: UNKNOWN 1023708 Source: UBUNTU Type: UNKNOWN USN-1006-1 Source: VUPEN Type: UNKNOWN ADV-2010-2722 Source: VUPEN Type: UNKNOWN ADV-2011-0212 Source: VUPEN Type: UNKNOWN ADV-2011-0552 Source: CCN Type: Red Hat Bugzilla Bug 570349 CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054 qt, webkitgtk: multiple security vulnerabilities in WebKit Source: XF Type: UNKNOWN safari-righttoleft-code-exec(56835) Source: CCN Type: iDefense Labs Public Advisory: 03.11.10 Multiple Vendor WebKit HTML Element Use After Free Vulnerability Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:6810 Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report Source: CCN Type: ZDI-10-152 Apple WebKit RTL LineBox Overflow Remote Code Execution Vulnerability | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |