Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22677

Опубликовано: 05 июл. 2022
Источник: redhat
CVSS3: 3.1

Описание

A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

A vulnerability was found in WebKitGTK. This issue occurs due to a logic issue in video self-preview feature in a webRTC call, which can be interrupted if the user answers a phone call or the audio capture is interrupted. This flaw allows a remote attacker to perform a denial of service attack.

Отчет

The vulnerability does not affect RHEL because WebRTC code is not included in any WebKitGTK releases thus far.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6webkitgtkNot affected
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 8webkit2gtk3Not affected
Red Hat Enterprise Linux 9webkit2gtk3Not affected
Red Hat Enterprise Linux 7 Extended Lifecycle Supportwebkitgtk4FixedRHSA-2025:1036407.07.2025

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-404
https://bugzilla.redhat.com/show_bug.cgi?id=2104788webkitgtk: the video in a webRTC call may be interrupted if the audio capture gets interrupted

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 3 лет назад

A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

CVSS3: 4.3
nvd
больше 3 лет назад

A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

CVSS3: 4.3
debian
больше 3 лет назад

A logic issue in the handling of concurrent media was addressed with i ...

CVSS3: 4.3
github
больше 3 лет назад

A logic issue in the handling of concurrent media was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. Video self-preview in a webRTC call may be interrupted if the user answers a phone call.

CVSS3: 4.3
fstec
больше 3 лет назад

Уязвимость модулей отображений веб-страниц WPE WebKit и WebKitGTK, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю оказать воздействие на целостность данных

3.1 Low

CVSS3