Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8720

Опубликовано: 29 окт. 2019
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

Отчет

This flaw is rated as 'Moderate' as the WebKitGTK package is shipped as a dependency for the Gnome package. Red Hat Enterprise Linux does not ship any WebKitGTK-based web browser where this flaw would present a higher severity major threat.

Меры по смягчению последствий

Red Hat has investigated whether possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6webkitgtkWill not fix
Red Hat Enterprise Linux 7webkitgtk3Will not fix
Red Hat Enterprise Linux 7webkitgtk4FixedRHSA-2020:403529.09.2020
Red Hat Enterprise Linux 8webkit2gtk3FixedRHSA-2020:445104.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1876611webkitgtk: Multiple memory corruption issues leading to arbitrary code execution

EPSS

Процентиль: 92%
0.08241
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CVSS3: 8.8
nvd
больше 2 лет назад

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

CVSS3: 8.8
debian
больше 2 лет назад

A vulnerability was found in WebKit. The flaw is triggered when proces ...

CVSS3: 8.8
github
больше 2 лет назад

A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.

suse-cvrf
больше 5 лет назад

Security update for webkit2gtk3

EPSS

Процентиль: 92%
0.08241
Низкий

8.8 High

CVSS3