PT-2010-3409 · Google+1 · Google Chrome+1

Drew Yao

+1

·

Published

2010-09-24

·

Updated

2024-02-02

·

CVE-2010-1772

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 5.0.375.70 WebKit versions prior to r59859
Description A use-after-free issue in page/Geolocation.cpp in WebCore allows remote attackers to execute arbitrary code or cause a denial of service via a crafted web site. This is related to the failure to stop timers associated with geolocation upon deletion of a document.
Recommendations For Google Chrome versions prior to 5.0.375.70, update to version 5.0.375.70 or later to resolve the issue. For WebKit versions prior to r59859, update to version r59859 or later to resolve the issue. As a temporary workaround, consider disabling geolocation features in affected versions until a patch is available.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2010-1772

Affected Products

Google Chrome
Webkit