Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.
A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 5.0.375.70 (excluding) | |
Chromium-browser | Ubuntu | lucid | * |
Qt4-x11 | Ubuntu | jaunty | * |
Qt4-x11 | Ubuntu | karmic | * |
Qt4-x11 | Ubuntu | lucid | * |
Webkit | Ubuntu | hardy | * |
Webkit | Ubuntu | jaunty | * |
Webkit | Ubuntu | karmic | * |
Webkit | Ubuntu | lucid | * |
Webkit | Ubuntu | upstream | * |