PT-2018-11100 · Apple+2 · Wpe Webkit+3

Published

2018-06-12

·

Updated

2020-08-24

·

CVE-2018-12293

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebKitGTK+ versions prior to 2.20.3 WPE WebKit versions prior to 2.20.1
Description The issue is related to a heap-based buffer overflow in the getImageData function within the ImageBufferCairo class. This overflow is triggered by an integer overflow and can be exploited by crafted HTML content.
Recommendations For WebKitGTK+ versions prior to 2.20.3, update to version 2.20.3 or later. For WPE WebKit versions prior to 2.20.1, update to version 2.20.1 or later.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1892
CVE-2018-12293
USN-3687-1

Affected Products

Alt Linux
Ubuntu
Wpe Webkit
Webkitgtk