Red Hat Bugzilla – Bug 627712
CVE-2010-1806 webkit: memory corruption in handling of run-in styling (ZDI-CAN-806)
Last modified: 2015-08-05 04:18:54 EDT
A use after free issue exists in WebKit's handling of elements with run-in styling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of object pointers. Credit to wushi of team509, working with TippingPoint's Zero Day Initiative for reporting this issue. References: https://bugs.webkit.org/show_bug.cgi?id=41375 http://trac.webkit.org/changeset/63772
This is now public: http://support.apple.com/kb/HT4333