CVE Vulnerabilities

CVE-2010-1416

Published: Jun 11, 2010 | Modified: Sep 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly restrict the reading of a canvas that contains an SVG image pattern from a different web site, which allows remote attackers to read images from other sites via a crafted canvas, related to a cross-site image capture issue.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 4.0.5 (including)
Safari Apple 4.0 (including) 4.0 (including)
Safari Apple 4.0.0b (including) 4.0.0b (including)
Safari Apple 4.0.1 (including) 4.0.1 (including)
Safari Apple 4.0.2 (including) 4.0.2 (including)
Safari Apple 4.0.3 (including) 4.0.3 (including)
Safari Apple 4.0.4 (including) 4.0.4 (including)
Webkit Apple * *
Chromium-browser Ubuntu devel *
Chromium-browser Ubuntu lucid *
Chromium-browser Ubuntu maverick *
Chromium-browser Ubuntu natty *
Chromium-browser Ubuntu oneiric *
Qt4-x11 Ubuntu jaunty *
Qt4-x11 Ubuntu karmic *
Qt4-x11 Ubuntu lucid *
Webkit Ubuntu hardy *
Webkit Ubuntu jaunty *
Webkit Ubuntu karmic *
Webkit Ubuntu lucid *
Webkit Ubuntu upstream *

References