CVE-2019-8710
Description
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iCloud for Windows 11.0. Processing maliciously crafted web content may lead to arbitrary code execution.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux 7webkitgtk4-0:2.28.2-2.el7RHSA-2020:40352020-09-29T00:00:00Z Red Hat Enterprise Linux 8webkit2gtk3-0:2.28.4-1.el8RHSA-2020:44512020-11-04T00:00:00Z Package stateβ¦
Description
webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | webkitgtk4-0:2.28.2-2.el7 | RHSA-2020:4035 | 2020-09-29T00:00:00Z |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.28.4-1.el8 | RHSA-2020:4451 | 2020-11-04T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix |
Apply commands
yum update -y webkitgtk4
# or:
dnf upgrade -y webkitgtk4
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.26.0-1 |
| sid | Fixed | 2.26.0-1 |
| forky | Fixed | 2.26.0-1 |
| bullseye | Fixed | 2.26.0-1 |
| bookworm | Fixed | 2.26.0-1 |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
References
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.