Vulnerability Description
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 7.0.517.44 | |
| Webkitgtk | Webkitgtk | 1.2.6 |
| Fedoraproject | Fedora | 13 |
Related Weaknesses (CWE)
References
- http://code.google.com/p/chromium/issues/detail?id=55257Release NotesVendor Advisory
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htMailing ListThird Party Advisory
- http://secunia.com/advisories/42109Broken Link
- http://secunia.com/advisories/43086Broken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlNot Applicable
- http://www.securityfocus.com/bid/45719Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2011/0216Not Applicable
- http://www.vupen.com/english/advisories/2011/0552Not Applicable
- https://bugs.webkit.org/show_bug.cgi?id=45611Permissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=656118Issue TrackingPatchThird Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=55257Release NotesVendor Advisory
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlVendor Advisory
FAQ
What is CVE-2010-4198?
CVE-2010-4198 is a vulnerability with a CVSS score of 8.8 (HIGH). WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (m...
How severe is CVE-2010-4198?
CVE-2010-4198 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-4198?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome, Webkitgtk Webkitgtk, Fedoraproject Fedora.