PT-2023-5289 · Apple+6 · Apple Macos+6
Joaxcar
+1
·
Publicado
2023-07-24
·
Atualizado
2025-01-28
·
CVE-2023-40397
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
macOS Ventura versions prior to 13.5
WebKitGTK (affected versions not specified)
WPE WebKit (affected versions not specified)
Description
The issue is related to errors in handling input data during code syntax analysis, which may allow a remote attacker to execute arbitrary javascript code. This can be achieved through the exploitation of vulnerabilities in the WebKitGTK and WPE WebKit modules, used for displaying web pages.
Recommendations
For macOS Ventura, update to version 13.5 to resolve the issue.
For WebKitGTK, restrict access to vulnerable modules to minimize the risk of exploitation until a patch is available.
For WPE WebKit, consider disabling the execution of javascript code in the affected modules as a temporary workaround until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability in WebKitGTK and WPE WebKit.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse