CVE-2019-8720
KEVmassMemory Corruption in WebKitGTK/WPE WebKit Enables Arbitrary Code Execution
CISA: WebKitGTK Memory Corruption Vulnerability
CVE-2019-8720 is a memory corruption flaw (CWE-119) in the WebKit engine as packaged in WebKitGTK and WPE WebKit, in which multiple memory-handling errors can be triggered by processing maliciously crafted web content. An attacker who gets a user to load attacker-controlled HTML — for example through an application that uses WebKitGTK to render email, feeds, or other web content — can corrupt memory and potentially execute arbitrary code with the privileges of that application. The CVSS 3.1 score of 8.8 (high) reflects that the attack path is network-based, requires no privileges but does require user interaction, and yields high impact on confidentiality, integrity, and availability. Users of WebKitGTK and WPE WebKit, including the packages shipped with Red Hat Enterprise Linux and its desktop, EUS, and architecture-specific variants, are affected. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, indicating known exploitation in the wild; no public proof-of-concept is known, and EPSS estimates a 1.6% probability of exploitation in the next 30 days.
What to do: Apply updated WebKitGTK/WPE WebKit packages per vendor instructions — for Red Hat Enterprise Linux, install the corrected packages from Red Hat security errata for your release — and prioritize systems where users view untrusted HTML, such as mail, feed, or desktop applications that embed WebKitGTK. As an interim mitigation, avoid rendering untrusted web content in applications that use WebKitGTK. Inventory hosts for webkitgtk/webkit2gtk packages and confirm they are on the patched release for your Red Hat Enterprise Linux version.
| WebKitGTK | — |
| WPE WebKit | — |
| Red Hat Enterprise Linux | — |
| Red Hat Enterprise Linux Desktop | — |
| Red Hat Enterprise Linux EUS | — |
| Red Hat Enterprise Linux for ARM64 EUS | — |
| Red Hat Enterprise Linux for IBM Z Systems | — |
| Red Hat CodeReady Linux Builder | — |
| Red Hat CodeReady Linux Builder EUS | — |
| Red Hat CodeReady Linux Builder for ARM64 EUS | — |
| Red Hat CodeReady Linux Builder for IBM Z Systems EUS | — |
| Red Hat CodeReady Linux Builder for POWER Little Endian EUS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
- Affected
- WebKitGTK WebKitGTK
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- webkitgtkwpewebkitredhat
- Products
- webkitgtk, wpe webkit, codeready linux builder, codeready linux builder eus, codeready linux builder for arm64 eus, codeready linux builder for ibm z systems eus, codeready linux builder for power little endian eus, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux for arm64 eus, enterprise linux for ibm z systems
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.