First published: Thu Jun 14 2018(Updated: )
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Webkitgtk Webkitgtk\+ | <2.20.3 | |
Wpewebkit Wpe Webkit | <2.20.1 | |
ubuntu/webkit2gtk | <2.20.3-0ubuntu0.17.10.1 | 2.20.3-0ubuntu0.17.10.1 |
ubuntu/webkit2gtk | <2.20.3-0ubuntu0.18.04.1 | 2.20.3-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.20.3 | 2.20.3 |
ubuntu/webkit2gtk | <2.20.3-0ubuntu0.16.04.1 | 2.20.3-0ubuntu0.16.04.1 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.3-1~deb11u1 2.44.2-1~deb12u1 2.44.3-1~deb12u1 2.44.3-1 2.44.4-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12293 is a vulnerability in WebKitGTK+ and WPE WebKit that could lead to a heap-based buffer overflow.
The vulnerability in CVE-2018-12293 is triggered by an integer overflow in the getImageData function of the ImageBufferCairo class in WebKit.
The severity of the vulnerability in CVE-2018-12293 is rated as high with a severity value of 8.8.
The vulnerability in CVE-2018-12293 affects WebKitGTK+ versions prior to 2.20.3 and WPE WebKit versions prior to 2.20.1.
To fix the vulnerability in CVE-2018-12293, update to WebKitGTK+ version 2.20.3 or later, or update to WPE WebKit version 2.20.1 or later.