Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1766

Опубликовано: 07 июн. 2010
Источник: redhat
CVSS2: 6.8

Описание

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qtWill not fix
Red Hat Enterprise Linux 6webkitgtkNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=596494WebKit: off-by-one memory corruption flaw WebSocketHandshake::readServerHandshake()

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

nvd
больше 15 лет назад

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

debian
больше 15 лет назад

Off-by-one error in the WebSocketHandshake::readServerHandshake functi ...

github
больше 3 лет назад

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

6.8 Medium

CVSS2