CVE-2017-1000121: Buffer Overflow
Published Nov 1, 2017
·Updated
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
Affected Software
1 affected component
WebKitGTK Webkitgtk\+<2.16.3
Remediation
Patch Available
Event History
Nov 1, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-1000121?
CVE-2017-1000121 has a medium severity due to the potential for integer overflow and buffer overflow vulnerabilities.
2
How do I fix CVE-2017-1000121?
To fix CVE-2017-1000121, update WebKitGTK+ to version 2.16.3 or later.
3
What are the potential consequences of CVE-2017-1000121?
The consequences of CVE-2017-1000121 include the possibility of remote code execution through buffer overflow in the UI process.
4
Is CVE-2017-1000121 present in Apple products?
CVE-2017-1000121 does not affect Apple products.
5
Which versions of WebKitGTK+ are affected by CVE-2017-1000121?
WebKitGTK+ versions prior to 2.16.3 are affected by CVE-2017-1000121.