Google Chrome before 17.0.963.46 does not properly perform casts of variables during handling of a column span, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document.
References
Link | Resource |
---|---|
http://code.google.com/p/chromium/issues/detail?id=105459 | Exploit Patch Vendor Advisory |
http://googlechromereleases.blogspot.com/2012/02/stable-channel-update.html | Release Notes Vendor Advisory |
http://support.apple.com/kb/HT5400 | Third Party Advisory |
http://lists.apple.com/archives/security-announce/2012/Jul/msg00000.html | Mailing List Third Party Advisory |
http://support.apple.com/kb/HT5485 | Third Party Advisory |
http://lists.apple.com/archives/security-announce/2012/Sep/msg00001.html | Mailing List Third Party Advisory |
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html | Mailing List Third Party Advisory |
http://support.apple.com/kb/HT5503 | Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14948 | Third Party Advisory |
Information
Published : 2012-02-08 20:10
Updated : 2020-04-17 06:32
NVD link : CVE-2011-3958
Mitre link : CVE-2011-3958
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
apple
- itunes
- safari
- iphone_os
- chrome