PT-2019-2585 · Gtk++4 · Webkitgtk+4

Dhiraj

·

Published

2019-02-14

·

Updated

2024-06-15

·

CVE-2019-8375

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebKitGTK+ versions prior to 2.22.7 WebKitGTK versions prior to 2.23.91
Description The issue is caused by a buffer overflow in the UIProcess subsystem of WebKitGTK+, allowing a remote attacker to potentially cause a denial of service or impact the confidentiality and integrity of protected information. The problem is related to the script dialog size exceeding the web view size. This issue affects products such as GNOME Web (also known as Epiphany).
Recommendations For WebKitGTK+ versions prior to 2.22.7, update to version 2.22.7 or later to resolve the issue. For WebKitGTK versions prior to 2.23.91, update to version 2.23.91 or later to resolve the issue. As a temporary workaround, consider restricting access to the UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp modules until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1453
BDU:2019-02463
CVE-2019-8375
OPENSUSE-SU-2019:1206-1
OPENSUSE-SU-2019_1206-1
OPENSUSE-SU-2019_1316-1
OPENSUSE-SU-2024:11506-1
SUSE-SU-2019:0890-1
SUSE-SU-2019:1030-1
SUSE-SU-2019_0890-1
SUSE-SU-2019_1030-1
USN-3948-1

Affected Products

Alt Linux
Gnome Web
Suse
Ubuntu
Webkitgtk