CVE-2010-1386

NameCVE-2010-1386
Descriptionpage/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
NVD severityhigh (attack range: remote)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)squeeze (security), squeeze6.0.472.63~r59945-5+squeeze6fixed
wheezy, wheezy (security)37.0.2062.120-1~deb7u1fixed
jessie, sid40.0.2214.111-1fixed
webkit (PTS)squeeze1.2.7-0+squeeze2fixed
squeeze (security)1.2.7-0+squeeze1fixed
wheezy1.8.1-3.4fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)5.0.342.9~r43360-1high
webkitsource(unstable)1.2.2-1high

Notes

[lenny] - webkit <no-dsa> (Unmaintained in Lenny, only affects fringe apps)
https://bugs.webkit.org/show_bug.cgi?id=36255
http://trac.webkit.org/changeset/56188

Search for package or bug name: Reporting problems