CVE-2017-1000121
01.11.2017, 21:29
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.Enginsight
| Vendor | Product | Version |
|---|---|---|
| webkitgtk | webkitgtk\+ | 𝑥 < 2.16.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit |
| ||||||||||||||||||||||||||||||||||
| qtwebkit-opensource-src |
| ||||||||||||||||||||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||||||||||||||||||||
| webkit2gtk |
| ||||||||||||||||||||||||||||||||||
| webkitgtk |
|