Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.
| Software | From | Fixed in |
|---|---|---|
| google / chrome | - | 5.0.375.127 |
| webkitgtk / webkitgtk | - | 1.2.5 |
| canonical / ubuntu_linux | 10.10 | 10.10.x |
| canonical / ubuntu_linux | 9.10 | 9.10.x |
| canonical / ubuntu_linux | 10.04 | 10.04.x |