The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Feb 24, 2019 |
| Oracle Solaris | — | Upgrade library/desktop/webkitgtk4 to version 2.24.4-11.4.16.0.1.1.0 on Solaris 11.4 | Dec 18, 2019 | Feb 24, 2019 |
| Suse | — | Upgrade webkit-jsc-4Upgrade libwebkit2gtk-4_0-37-32bitUpgrade libjavascriptcoregtk-4_0-18-32bitUpgrade typelib-1_0-webkit2-4_0Upgrade typelib-1_0-webkit2webextension-4_0Upgrade webkit2gtk3-plugin-process-gtk2Upgrade libwebkit2gtk3-langUpgrade libwebkit2gtk-4_0-37Upgrade webkit2gtk3-develUpgrade webkit2gtk3-minibrowserUpgrade webkit2gtk-4_0-injected-bundlesUpgrade libjavascriptcoregtk-4_0-18Upgrade typelib-1_0-javascriptcore-4_0 | Apr 16, 2019 | Feb 24, 2019 |
| Ubuntu | — | Upgrade libwebkit2gtk-4.0-37Upgrade libjavascriptcoregtk-4.0-18 | Apr 25, 2019 | Feb 24, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub