REDHAT-BUG-2238943: Use After Free
Published Sep 14, 2023
·Updated
Versions affected: WebKitGTK and WPE WebKit before 2.40.1. Credit to hazbinhotel working with Trend Micro Zero Day Initiative. Impact: Processing web content may lead to arbitrary code execution. Description: A use-after-free issue was addressed with improved memory management.
Affected Software
2 affected components
WebKit WebKitGTK<2.40.1
WebKit WPE WebKit<2.40.1
Event History
Sep 14, 2023
Data Sourced
via Red Hat·01:43 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2238943?
The severity of REDHAT-BUG-2238943 is high due to the risk of arbitrary code execution.
2
How do I fix REDHAT-BUG-2238943?
To fix REDHAT-BUG-2238943, update to WebKitGTK and WPE WebKit version 2.40.1 or later.
3
What products are affected by REDHAT-BUG-2238943?
The products affected by REDHAT-BUG-2238943 are WebKitGTK and WPE WebKit versions prior to 2.40.1.
4
What type of issue is REDHAT-BUG-2238943 classified as?
REDHAT-BUG-2238943 is classified as a use-after-free vulnerability.
5
Who credited the discovery of REDHAT-BUG-2238943?
The discovery of REDHAT-BUG-2238943 is credited to a researcher working with Trend Micro Zero Day Initiative.