CVE-2019-8720: WebKitGTK Memory Corruption Vulnerability
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
Other sources
WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
— CISA
WebKitGTK Security Advisory WSA-2019-0005 describes the following issue:
CVE-2019-8720
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.26.0 - Upgrade
Upgrade
WebKitGTKto a version that resolves this vulnerability.Fixed in 2.26.0 - Upgrade
Upgrade
WPE WebKitto a version that resolves this vulnerability.Fixed in 2.26.0