CVE-2018-12293
19.06.2018, 21:29
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 17.10 |
| canonical | ubuntu_linux | 18.04 |
| webkitgtk | webkitgtk\+ | 𝑥 < 2.20.3 |
| wpewebkit | wpe_webkit | 𝑥 < 2.20.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit |
| ||||||||||||||||||||||||||||||||
| qtwebkit-opensource-src |
| ||||||||||||||||||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||||||||||||||||||
| webkit2gtk |
| ||||||||||||||||||||||||||||||||
| webkitgtk |
|
References