vendor:
WebKit
by:
MJ Keith
9,3
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: WebKit
Affected Version From: 2.1
Affected Version To: 2.3
Patch Exists: YES
Related CWE: CVE-2010-1759
CPE: a:apple:webkit
Metasploit:
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2010-2300/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-2300/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2010-1759/, https://www.rapid7.com/db/vulnerabilities/apple-safari-cve-2010-1759/, https://www.rapid7.com/db/vulnerabilities/apple-itunes-cve-2010-1759/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Moto Droidx2, 2.1-2.3 emulator
2010
CVE-2010-1759 webkit normalize bug
This exploit is a buffer overflow vulnerability in the WebKit normalize function. It was tested on Moto Droidx2 running 2.2 and 2.3, as well as a 2.1-2.3 emulator. The exploit uses a spray of 0x52 bytes followed by a shellcode to gain remote access to the device. The shellcode contains the IP address and port of the attacker's machine.
Mitigation:
The best way to mitigate this vulnerability is to update the device to the latest version of the WebKit library.