CVE-2012-5851

NameCVE-2012-5851
Descriptionhtml/parser/XSSAuditor.cpp in WebCore in WebKit, as used in Google Chrome through 22 and Safari 5.1.7, does not consider all possible output contexts of reflected data, which makes it easier for remote attackers to bypass a cross-site scripting (XSS) protection mechanism via a crafted string, aka rdar problem 12019108.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)wheezy, wheezy (security)37.0.2062.120-1~deb7u1vulnerable
jessie (security), jessie57.0.2987.98-1~deb8u1vulnerable
stretch62.0.3202.89-1~deb9u1vulnerable
stretch (security)64.0.3282.119-1~deb9u1vulnerable
buster62.0.3202.89-1vulnerable
sid66.0.3359.26-2vulnerable
webkit (PTS)wheezy1.8.1-3.4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)(unfixed)unimportant
webkitsource(unstable)(unfixed)unimportant

Notes

https://bugs.webkit.org/show_bug.cgi?id=92692
Incomplete mitigation feature, not a security vulnerability per se

Search for package or bug name: Reporting problems