High severity7.5NVD Advisory· Published Dec 22, 2010· Updated Apr 29, 2026
CVE-2010-4577
CVE-2010-4577
Description
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
Affected products
6cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- trac.webkit.org/changeset/72685nvdMailing ListPatch
- trac.webkit.org/changeset/72685/trunk/WebCore/css/CSSParser.cppnvdMailing ListPatch
- code.google.com/p/chromium/issues/detailnvdExploitIssue TrackingMailing List
- lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlnvdMailing ListThird Party Advisory
- secunia.com/advisories/42648nvdBroken LinkThird Party Advisory
- secunia.com/advisories/43086nvdBroken LinkThird Party Advisory
- www.debian.org/security/2011/dsa-2188nvdMailing ListThird Party Advisory
- www.gentoo.org/security/en/glsa/glsa-201012-01.xmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2011-0177.htmlnvdBroken LinkThird Party Advisory
- www.securityfocus.com/bid/45722nvdBroken LinkThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2011/0216nvdBroken LinkThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A13953nvdBroken LinkThird Party Advisory
- googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlnvdRelease Notes
- bugs.webkit.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.