CVE-2018-12911: Critical severity webkitgtk+ vulnerability
Last updated 24 July 2024
Other sources
WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the getsimpleglobs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-12911?
CVE-2018-12911 is a vulnerability in WebKitGTK+ 2.20.3 that allows an off-by-one error and an out-of-bounds write in the get_simple_globs functions.
How severe is CVE-2018-12911?
CVE-2018-12911 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2018-12911?
WebKitGTK+ versions 2.20.3, 2.20.4, and 2.36.4-2.42.1 are affected by CVE-2018-12911.
What is the recommended remedy for CVE-2018-12911?
Upgrade to WebKitGTK+ version 2.20.5-0ubuntu0.18.04.1 for Ubuntu or apply the relevant updates provided by your Linux distribution or vendor.
Where can I find more information about CVE-2018-12911?
You can find more information about CVE-2018-12911 at the following references: [CVE-2018-12911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12911), [WSA-2018-0006](https://webkitgtk.org/security/WSA-2018-0006.html), [USN-3743-1](https://ubuntu.com/security/notices/USN-3743-1).