The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Chrome | * | 5.0.375.127 (excluding) | |
Chromium-browser | Ubuntu | lucid | * |
Chromium-browser | Ubuntu | upstream | * |
Webkit | Ubuntu | hardy | * |
Webkit | Ubuntu | jaunty | * |
Webkit | Ubuntu | karmic | * |
Webkit | Ubuntu | lucid | * |
Webkit | Ubuntu | upstream | * |
Red Hat Enterprise Linux 6 | RedHat | webkitgtk-0:1.2.6-2.el6_0 | * |