CVE-2010-1386

NameCVE-2010-1386
Descriptionpage/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium-browser (PTS)jessie, jessie (lts)57.0.2987.98-1~deb8u1fixed
stretch (security), stretch (lts), stretch71.0.3578.80-1~deb9u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromium-browsersource(unstable)5.0.342.9~r43360-1
webkitsource(unstable)1.2.2-1

Notes

[lenny] - webkit <no-dsa> (Unmaintained in Lenny, only affects fringe apps)
https://bugs.webkit.org/show_bug.cgi?id=36255
http://trac.webkit.org/changeset/56188

Search for package or bug name: Reporting problems