ZeroHour

CVE-2023-2203

CVSS 3.1
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

Vendors
webkitgtkredhat
Products
webkit2gtk3, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.