CVE-2023-25361: Use After Free
Published Mar 2, 2023
·Updated
A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
Affected Software
2 affected componentsFixes available
WebKitGTK WebKitGTK<2.36.8
redhat/webkitgtk<2.36.8
2.36.8
Event History
Mar 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 3, 2023
Data Sourced
via Red Hat·08:26 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-25361?
CVE-2023-25361 is a use-after-free vulnerability in WebKitGTK before version 2.36.8 that allows attackers to execute code remotely.
2
How severe is CVE-2023-25361?
CVE-2023-25361 has a severity score of 8.8 (high).
3
What software versions are affected by CVE-2023-25361?
Versions of WebKitGTK before 2.36.8 are affected by CVE-2023-25361.
4
How can an attacker exploit CVE-2023-25361?
An attacker can exploit CVE-2023-25361 to execute code remotely.
5
Is there a fix available for CVE-2023-25361?
Yes, upgrading to WebKitGTK version 2.36.8 or later fixes the CVE-2023-25361 vulnerability.