vulnerability
SUSE: CVE-2023-42916: SUSE Linux Security Advisory
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:C/I:N/A:N) | Nov 30, 2023 | Dec 19, 2023 | Jan 28, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Nov 30, 2023
Added
Dec 19, 2023
Modified
Jan 28, 2025
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Solutions
suse-upgrade-libjavascriptcoregtk-4_0-18suse-upgrade-libjavascriptcoregtk-4_0-18-32bitsuse-upgrade-libjavascriptcoregtk-4_1-0suse-upgrade-libjavascriptcoregtk-4_1-0-32bitsuse-upgrade-libjavascriptcoregtk-6_0-1suse-upgrade-libwebkit2gtk-4_0-37suse-upgrade-libwebkit2gtk-4_0-37-32bitsuse-upgrade-libwebkit2gtk-4_1-0suse-upgrade-libwebkit2gtk-4_1-0-32bitsuse-upgrade-libwebkit2gtk3-langsuse-upgrade-libwebkitgtk-6_0-4suse-upgrade-typelib-1_0-javascriptcore-4_0suse-upgrade-typelib-1_0-javascriptcore-4_1suse-upgrade-typelib-1_0-javascriptcore-6_0suse-upgrade-typelib-1_0-webkit-6_0suse-upgrade-typelib-1_0-webkit2-4_0suse-upgrade-typelib-1_0-webkit2-4_1suse-upgrade-typelib-1_0-webkit2webextension-4_0suse-upgrade-typelib-1_0-webkit2webextension-4_1suse-upgrade-typelib-1_0-webkitwebprocessextension-6_0suse-upgrade-webkit-jsc-4suse-upgrade-webkit-jsc-4-1suse-upgrade-webkit-jsc-6-0suse-upgrade-webkit2gtk-4_0-injected-bundlessuse-upgrade-webkit2gtk-4_1-injected-bundlessuse-upgrade-webkit2gtk3-develsuse-upgrade-webkit2gtk3-minibrowsersuse-upgrade-webkit2gtk3-soup2-develsuse-upgrade-webkit2gtk3-soup2-minibrowsersuse-upgrade-webkit2gtk4-develsuse-upgrade-webkit2gtk4-minibrowsersuse-upgrade-webkitgtk-4-0-langsuse-upgrade-webkitgtk-4-1-langsuse-upgrade-webkitgtk-6-0-langsuse-upgrade-webkitgtk-6_0-injected-bundles
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.