PT-2018-10728 · Webkit+2 · Webkitgtk+2

Dhiraj Mishra

+2

·

Publicado

2018-06-01

·

Atualizado

2024-06-15

·

CVE-2018-11646

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WebKitGTK+ versions prior to 2.21.4
Description The issue arises from the webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL functions in UIProcess/API/glib/WebKitFaviconDatabase.cpp of WebKit, which is used in WebKitGTK+. The functions mishandle an unset pageURL, resulting in an application crash.
Recommendations For WebKitGTK+ versions prior to 2.21.4, update to version 2.21.4 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2018-1892
ALT-PU-2018-2308
CVE-2018-11646
MGASA-2018-0302
OPENSUSE-SU-2018_2285-1
OPENSUSE-SU-2018_3473-1
OPENSUSE-SU-2024:11506-1
SUSE-SU-2018:2075-1
SUSE-SU-2018:3387-1

Produtos afetados

Alt Linux
Suse
Webkitgtk