CVE-2023-39928
06.10.2023, 16:15
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| webkitgtk | webkitgtk | 2.40.5 |
| debian | debian_linux | 11.0 |
| debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkit2gtk |
| ||||||||||||
| wpewebkit |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit-opensource-src |
| ||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||
| webkit2gtk |
| ||||||||||||||||
| webkitgtk |
| ||||||||||||||||
| wpewebkit |
|
Common Weakness Enumeration
References