First published: Mon Mar 02 2020(Updated: )
accessibility/AXObjectCache.cpp in WebKit, as used in WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4, allows a denial of service (application crash) because maintenance of the m_deferredFocusedNodeChange data structure mishandles removal. Upstream patch: <a href="https://trac.webkit.org/changeset/257292/webkit">https://trac.webkit.org/changeset/257292/webkit</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <2.28.0 | 2.28.0 |
ubuntu/webkit2gtk | <2.28.0-0ubuntu0.18.04.3 | 2.28.0-0ubuntu0.18.04.3 |
ubuntu/webkit2gtk | <2.28.0-0ubuntu0.19.10.2 | 2.28.0-0ubuntu0.19.10.2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0-1ubuntu2 | 2.28.0-1ubuntu2 |
ubuntu/webkit2gtk | <2.28.0 | 2.28.0 |
debian/webkit2gtk | 2.44.2-1~deb11u1 2.44.2-1~deb12u1 2.44.2-1 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.44.2-1 | |
WebKitGTK+ | <2.28.0 | |
wpewebkit WPE WebKit | <2.28.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Debian GNU/Linux | =10.0 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.1 | |
Fedora | =30 | |
Fedora | =31 | |
Debian | =10.0 | |
Ubuntu | =18.04 | |
Ubuntu | =19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10018 is a memory corruption vulnerability in WebKitGTK and WPE WebKit versions before 2.28.0.
CVE-2020-10018 has a severity rating of 9.8 out of 10, making it a critical vulnerability.
CVE-2020-10018 may lead to arbitrary code execution.
CVE-2020-10018 has been fixed in version 2.28.0 of WebKitGTK and WPE WebKit with improved memory handling.
More information about CVE-2020-10018 can be found at the following references: [CVE-2020-10018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10018), [WebKit Changeset](https://trac.webkit.org/changeset/257292), [WebKitGTK Security Advisory](https://webkitgtk.org/security/WSA-2020-0003.html).