Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-13502

Опубликовано: 25 нояб. 2025
Источник: debian

Описание

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.50.2-1package
wpewebkitfixed2.50.2-1package
wpewebkitignoredtrixiepackage
wpewebkitignoredbookwormpackage
wpewebkitend-of-lifebullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2416300

  • https://webkitgtk.org/security/WSA-2025-0009.html

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

CVSS3: 7.5
nvd
2 месяца назад

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

CVSS3: 7.5
github
2 месяца назад

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

rocky
около 2 месяцев назад

Important: webkit2gtk3 security update

rocky
около 2 месяцев назад

Important: webkit2gtk3 security update