PT-2020-7575 · Webkitgtk+1 · Webkitgtk+1

Alexander E. Patrakov

·

Published

2020-02-17

·

Updated

2020-03-15

·

CVE-2013-7324

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webkit-GTK versions 2.x
Description The issue allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. This behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
Recommendations For Webkit-GTK version 2.x, consider disabling HTML5 audio/video support based on GStreamer as a temporary workaround until a patch is available. Restrict access to malicious javascript to minimize the risk of exploitation.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1481
CVE-2013-7324

Affected Products

Alt Linux
Webkitgtk