CVE-2011-3243
Publication date 14 October 2011
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | ||
16.04 LTS xenial |
Fixed 22.0
|
|
14.04 LTS trusty |
Fixed 22.0
|
|
qt4-x11 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
qtwebkit-source | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
webkit | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
webkitgtk | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
jdstrand
qt4-x11 unmaintained upstream (see README.webkit for details) marking chromium-browser as fixed since it has 22+ on all releases and they sync with upstream webkit every few weeks