CVE-2010-1766

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

References

http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html

http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html

http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html

http://secunia.com/advisories/40557

http://secunia.com/advisories/41856

http://secunia.com/advisories/43068

http://trac.webkit.org/changeset/56380

http://www.mandriva.com/security/advisories?name=MDVSA-2011:039

http://www.ubuntu.com/usn/USN-1006-1

http://www.vupen.com/english/advisories/2010/1801

http://www.vupen.com/english/advisories/2010/2722

http://www.vupen.com/english/advisories/2011/0212

http://www.vupen.com/english/advisories/2011/0552

https://bugs.webkit.org/show_bug.cgi?id=36339

https://bugzilla.redhat.com/show_bug.cgi?id=596494

Details

Source: MITRE

Published: 2010-07-22

Updated: 2013-02-07

Type: CWE-189

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:digia:qt:*:*:*:*:*:*:*:* versions up to 4.6.2 (inclusive)

cpe:2.3:a:webkit:webkit:*:*:*:*:*:*:*:* versions up to r56379 (inclusive)

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
75629openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
53764openSUSE Security Update : libwebkit (openSUSE-SU-2011:0024-1)NessusSuSE Local Security Checks
critical
52523Mandriva Linux Security Advisory : webkit (MDVSA-2011:039)NessusMandriva Local Security Checks
critical
50046Ubuntu 9.10 / 10.04 LTS / 10.10 : webkit vulnerabilities (USN-1006-1)NessusUbuntu Local Security Checks
critical
47724Fedora 12 : qt-4.6.3-8.fc12 (2010-11020)NessusFedora Local Security Checks
high
47723Fedora 13 : qt-4.6.3-8.fc13 (2010-11011)NessusFedora Local Security Checks
high