A stale layout root is set as an input element in WebKit in Google Chrome before Blink M13 when a child of a keygen with autofocus is accessed.
References
Link | Resource |
---|---|
https://bugs.chromium.org/p/chromium/issues/detail?id=83672 | Exploit Issue Tracking Mailing List Patch Vendor Advisory |
http://trac.webkit.org/browser/trunk/Source/WebCore/rendering/RenderObject.h?rev=86705#L1044 | Exploit Mailing List Vendor Advisory |
http://code.google.com/p/chromium/issues/detail?id=82063 | Exploit Issue Tracking Mailing List Vendor Advisory |
http://trac.webkit.org/changeset/86976 | Mailing List Patch Vendor Advisory |
http://trac.webkit.org/changeset/90568 | Mailing List Patch Vendor Advisory |
https://bugs.webkit.org/show_bug.cgi?id=57091 | Issue Tracking Patch Vendor Advisory |
http://trac.webkit.org/changeset/90848 | Mailing List Patch Vendor Advisory |
Configurations
Information
Published : 2019-11-06 13:15
Updated : 2019-11-13 09:54
NVD link : CVE-2011-2808
Mitre link : CVE-2011-2808
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
- blink