First published: Fri May 06 2022(Updated: )
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.40.5-1~deb11u1 2.42.1-1~deb11u2 2.40.5-1~deb12u1 2.42.1-1~deb12u1 2.42.1-2 | |
debian/wpewebkit | 2.38.6-1~deb11u1 2.38.6-1 2.42.1-1 | |
WebKitGTK+ | <=2.36.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30293 is a heap-based buffer overflow vulnerability found in WebKitGTK through version 2.36.0 and WPE WebKit.
CVE-2022-30293 has a severity score of 7.5, which is considered high.
WebKitGTK versions up to and including 2.36.0 and WPE WebKit are affected by CVE-2022-30293.
To fix CVE-2022-30293, upgrade to the latest versions of WebKitGTK or WPE WebKit as provided by the respective vendors.
You can find more information about CVE-2022-30293 at the links: [http://www.openwall.com/lists/oss-security/2022/05/30/1](http://www.openwall.com/lists/oss-security/2022/05/30/1), [https://bugs.webkit.org/show_bug.cgi?id=237187](https://bugs.webkit.org/show_bug.cgi?id=237187), [https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0](https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0).