Description
page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.
References (12)
Core 12
Core References
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
Third Party Advisory x_refsource_confirm
http://security-tracker.debian.org/tracker/CVE-2010-1386
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/2722
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43068
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1006-1
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/41856
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0212
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/42500
Various Sources x_refsource_confirm
http://trac.webkit.org/changeset/56188
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0552
Various Sources x_refsource_confirm
https://bugs.webkit.org/show_bug.cgi?id=36255
Scores
EPSS
0.0213
EPSS Percentile
80.1%
Details
CWE
CWE-264
Status
published
Products (2)
apple/webkit
r50173
apple/webkit
< r56187
Published
Aug 19, 2010
Tracked Since
Feb 18, 2026