PT-2023-6386 · Webkitgtk+9 · Webkitgtk+9

Marcin Icewall

+1

·

Published

2023-09-28

·

Updated

2024-08-20

·

CVE-2023-39928

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebKitGTK versions 2.40.5
Description A use-after-free vulnerability exists in the MediaRecorder API of WebKitGTK, which can be exploited by a specially crafted web page to cause memory corruption and potentially arbitrary code execution. A user would need to visit a malicious webpage to trigger this vulnerability.
Recommendations For WebKitGTK version 2.40.5, consider disabling the MediaRecorder API until a patch is available. Restrict access to the MediaRecorder API to minimize the risk of exploitation. Avoid using the MediaRecorder API in web pages until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2024:2126
ALSA-2024:2982
BDU:2023-07098
CESA-2024_2982
CVE-2023-39928
DSA-5527-1
DSA-5527-2
INFSA-2024_2126
INFSA-2024_2982
MGASA-2024-0148
OPENSUSE-SU-2023_4294-1
OPENSUSE-SU-2024_0004-1
RHSA-2024:2126
RHSA-2024:2982
RHSA-2024_2126
RHSA-2024_2982
RHSA-2025:10364
RLSA-2024:2982
SUSE-SU-2023:4209-1
SUSE-SU-2023:4211-1
SUSE-SU-2023:4294-1
SUSE-SU-2023:4339-1
SUSE-SU-2023:4978-1
SUSE-SU-2023_4978-1
SUSE-SU-2024:0002-1
SUSE-SU-2024:0003-1
SUSE-SU-2024:0004-1
USN-6426-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Webkitgtk