The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2019-02-24 13:29
Updated : 2024-11-21 04:49
NVD link : CVE-2019-8375
Mitre link : CVE-2019-8375
CVE.ORG link : CVE-2019-8375
JSON object : View
Products Affected
canonical
- ubuntu_linux
webkitgtk
- webkitgtk
- webkitgtk\+
opensuse
- leap
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer