Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-8375

Опубликовано: 24 фев. 2019
Источник: debian
EPSS Средний

Описание

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.24.1-1package

Примечания

  • https://github.com/WebKit/webkit/commit/6f9b511a115311b13c06eb58038ddc2c78da5531

  • https://trac.webkit.org/changeset/241515/webkit

  • https://www.inputzero.io/2019/02/fuzzing-webkit.html

  • Not covered by security support

EPSS

Процентиль: 95%
0.19285
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

CVSS3: 9.8
nvd
почти 7 лет назад

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

suse-cvrf
почти 7 лет назад

Security update for webkit2gtk3

suse-cvrf
почти 7 лет назад

Security update for webkit2gtk3

suse-cvrf
почти 7 лет назад

Security update for webkit2gtk3

EPSS

Процентиль: 95%
0.19285
Средний