The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade webkit2gtk | Jul 30, 2024 | Jun 19, 2018 |
| Gentoo Linux | — | Upgrade net-libs/webkit-gtk. | Aug 23, 2018 | Jun 19, 2018 |
| Oracle Solaris | — | Upgrade library/audio/taglib to version 1.11.1-11.4.3.0.1.1.0 on Solaris 11.4Upgrade library/desktop/webkitgtk4 to version 2.20.5-11.4.3.0.1.1.0 on Solaris 11.4Upgrade x11/library/libx11 to version 1.6.5-11.4.3.0.1.1.0 on Solaris 11.4Upgrade communication/im/pidgin to version 2.12.0-11.4.3.0.1.1.0 on Solaris 11.4 | Nov 19, 2018 | Jun 19, 2018 |
| Ubuntu | — | Upgrade libjavascriptcoregtk-4.0-18Upgrade libwebkit2gtk-4.0-37 | Jun 27, 2018 | Jun 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub