CVE-2019-8375

CRITICAL

Webkitgtk < 2.23.90 - Memory Corruption

Title source: rule

Description

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).

Exploits (1)

exploitdb WORKING POC
by Dhiraj Mishra · textdoslinux
https://www.exploit-db.com/exploits/46465

Scores

CVSS v3 9.8
EPSS 0.1928
EPSS Percentile 95.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (6)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
opensuse/leap 15.0
opensuse/leap 42.3
webkitgtk/webkitgtk < 2.23.90
webkitgtk/webkitgtk\+ < 2.22.6
Published Feb 24, 2019
Tracked Since Feb 18, 2026