CVE-2019-8375: Buffer Overflow
Last updated 24 July 2024
Other sources
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-8375?
CVE-2019-8375 is a vulnerability in the UIProcess subsystem in WebKitGTK and WebKitGTK+ that allows remote attackers to cause a denial of service or possibly have unspecified impact.
What is the severity of CVE-2019-8375?
CVE-2019-8375 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2019-8375?
CVE-2019-8375 affects WebKitGTK versions up to 2.23.90 and WebKitGTK+ versions up to 2.22.6.
How can CVE-2019-8375 be exploited?
CVE-2019-8375 can be exploited by remote attackers to cause a buffer overflow or have unspecified impact.
Are there any references related to CVE-2019-8375?
Yes, you can find references related to CVE-2019-8375 at the following links: http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00058.html, http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00005.html, and https://bugs.webkit.org/show_bug.cgi?id=184875.