CVE-2012-5112
Publication date 11 October 2012
Last updated 24 July 2024
Ubuntu priority
Use-after-free vulnerability in the SVG implementation in WebKit, as used in Google Chrome before 22.0.1229.94, allows remote attackers to execute arbitrary code via unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
qtwebkit-source | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
webkit | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
webkitgtk | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
jdstrand
r161037 (BUG=154983) does not affect webkit in Ubuntu https://trac.webkit.org/changeset/130855 may be the fix, but the upstream chromium bug is still private
References
Other references
- http://googlechromereleases.blogspot.com/2012/10/stable-channel-update_6105.html
- http://code.google.com/p/chromium/issues/detail?id=154987
- http://code.google.com/p/chromium/issues/detail?id=154983
- http://blog.chromium.org/2012/10/pwnium-2-results-and-wrap-up_10.html
- http://src.chromium.org/viewvc/chrome?view=rev&revision=161037
- https://www.cve.org/CVERecord?id=CVE-2012-5112