Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.69325
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2188-1)
Summary:The remote host is missing an update for the Debian 'webkit' package(s) announced via the DSA-2188-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'webkit' package(s) announced via the DSA-2188-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been discovered in WebKit, a Web content engine library for GTK+. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2010-1783

WebKit does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

CVE-2010-2901

The rendering implementation in WebKit allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVE-2010-4199

WebKit does not properly perform a cast of an unspecified variable during processing of an SVG element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document.

CVE-2010-4040

WebKit does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.

CVE-2010-4492

Use-after-free vulnerability in WebKit allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.

CVE-2010-4493

Use-after-free vulnerability in WebKit allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.

CVE-2010-4577

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to Type Confusion.

CVE-2010-4578

WebKit does not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to stale pointers.

CVE-2011-0482

WebKit does not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document.

CVE-2011-0778

WebKit does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

For the stable distribution (squeeze), these problems have been fixed in version 1.2.7-0+squeeze1.

For the testing distribution (wheezy), and the unstable distribution (sid), these problems have been fixed in version 1.2.7-1.

Security support for WebKit has been discontinued for the oldstable distribution (lenny). The current version in oldstable is not supported by upstream anymore and is affected by several security issues. Backporting fixes for these and any future issues has become unfeasible and therefore we need to drop our security support for the version in oldstable.

We recommend that you upgrade your webkit packages.

Affected Software/OS:
'webkit' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0474
Common Vulnerability Exposure (CVE) ID: CVE-2010-1783
http://lists.apple.com/archives/security-announce/2010//Jul/msg00001.html
http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
BugTraq ID: 42020
http://www.securityfocus.com/bid/42020
Debian Security Information: DSA-2188 (Google Search)
http://www.debian.org/security/2011/dsa-2188
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11820
http://www.redhat.com/support/errata/RHSA-2011-0177.html
http://secunia.com/advisories/41856
http://secunia.com/advisories/42314
http://secunia.com/advisories/43068
http://secunia.com/advisories/43086
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2010/2722
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0216
http://www.vupen.com/english/advisories/2011/0552
Common Vulnerability Exposure (CVE) ID: CVE-2010-2901
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11997
http://secunia.com/advisories/40743
SuSE Security Announcement: SUSE-SR:2011:009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2010-4040
BugTraq ID: 44241
http://www.securityfocus.com/bid/44241
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7646
http://secunia.com/advisories/41888
http://www.vupen.com/english/advisories/2010/2731
Common Vulnerability Exposure (CVE) ID: CVE-2010-4199
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11429
http://secunia.com/advisories/42109
Common Vulnerability Exposure (CVE) ID: CVE-2010-4492
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11475
http://secunia.com/advisories/42472
Common Vulnerability Exposure (CVE) ID: CVE-2010-4493
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12129
Common Vulnerability Exposure (CVE) ID: CVE-2010-4577
BugTraq ID: 45722
http://www.securityfocus.com/bid/45722
http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.html
http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml
http://trac.webkit.org/changeset/72685
http://trac.webkit.org/changeset/72685/trunk/WebCore/css/CSSParser.cpp
https://bugs.webkit.org/show_bug.cgi?id=49883
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13953
http://secunia.com/advisories/42648
Common Vulnerability Exposure (CVE) ID: CVE-2010-4578
BugTraq ID: 45390
http://www.securityfocus.com/bid/45390
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323
Common Vulnerability Exposure (CVE) ID: CVE-2011-0482
BugTraq ID: 45788
http://www.securityfocus.com/bid/45788
http://osvdb.org/70465
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14662
http://secunia.com/advisories/42951
XForce ISS Database: chrome-anchors-dos(64673)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64673
Common Vulnerability Exposure (CVE) ID: CVE-2011-0778
Debian Security Information: DSA-2166 (Google Search)
http://www.debian.org/security/2011/dsa-2166
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14228
http://secunia.com/advisories/43368
http://www.vupen.com/english/advisories/2011/0408
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.