The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Feb 24, 2019 |
| Oracle Solaris | — | Upgrade library/desktop/webkitgtk4 to version 2.24.4-11.4.16.0.1.1.0 on Solaris 11.4 | Dec 18, 2019 | Feb 24, 2019 |
| Suse | — | Upgrade webkit2gtk3-plugin-process-gtk2Upgrade typelib-1_0-webkit2webextension-4_0Upgrade webkit-jsc-4Upgrade libwebkit2gtk3-langUpgrade typelib-1_0-webkit2-4_0Upgrade libjavascriptcoregtk-4_0-18-32bitUpgrade libwebkit2gtk-4_0-37-32bitUpgrade webkit2gtk-4_0-injected-bundlesUpgrade libjavascriptcoregtk-4_0-18Upgrade webkit2gtk3-develUpgrade libwebkit2gtk-4_0-37Upgrade webkit2gtk3-minibrowserUpgrade typelib-1_0-javascriptcore-4_0 | Apr 16, 2019 | Feb 24, 2019 |
| Ubuntu | — | Upgrade libjavascriptcoregtk-4.0-18Upgrade libwebkit2gtk-4.0-37 | Apr 25, 2019 | Feb 24, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub