First published: Thu Mar 02 2023(Updated: )
A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | <=2.36.4-1~deb10u1 | 2.38.5-1~deb10u1 2.38.5-1~deb11u1 2.40.1-1~deb11u1 2.40.1-1 |
debian/wpewebkit | 2.38.5-1~deb11u1 2.38.6-1~deb11u1 2.38.6-1 | |
ubuntu/webkit2gtk | <2.38.6-0ubuntu0.20.04.1 | 2.38.6-0ubuntu0.20.04.1 |
ubuntu/webkit2gtk | <2.38.6-0ubuntu0.22.04.1 | 2.38.6-0ubuntu0.22.04.1 |
ubuntu/webkit2gtk | <2.38.6-0ubuntu0.22.10.1 | 2.38.6-0ubuntu0.22.10.1 |
WebKitGTK+ | <2.36.8 | |
Fedoraproject Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this use-after-free vulnerability is CVE-2023-25358.
The severity of CVE-2023-25358 is not specified in the provided information.
The use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK allows attackers to execute code remotely by manipulating memory after it has been freed.
The versions of WebKitGTK affected by CVE-2023-25358 are before 2.36.8.
The recommended versions of WebKitGTK to fix CVE-2023-25358 are 2.38.5-1~deb10u1, 2.38.5-1~deb11u1, 2.40.1-1~deb11u1, and 2.40.1-1.