CVE-2010-1766

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
22/07/2010
Last modified:
11/04/2025

Description

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digia:qt:*:*:*:*:*:*:*:* 4.6.2 (including)
cpe:2.3:a:webkit:webkit:*:*:*:*:*:*:*:* r56379 (including)


References to Advisories, Solutions, and Tools