CVE-2017-1000121
01.11.2017, 21:29
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.Enginsight
Vendor | Product | Version |
---|---|---|
webkitgtk | webkitgtk\+ | 𝑥 < 2.16.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
qtwebkit |
| ||||||||||||||||||||||||||||||||||
qtwebkit-opensource-src |
| ||||||||||||||||||||||||||||||||||
qtwebkit-source |
| ||||||||||||||||||||||||||||||||||
webkit2gtk |
| ||||||||||||||||||||||||||||||||||
webkitgtk |
|