[webkit-gtk] [webkit-security] WebKitGTK+ Security Advisory WSA-2018-0003

Michael Catanzaro mcatanzaro at igalia.com
Wed Apr 4 12:22:53 PDT 2018


On Wed, Apr 4, 2018 at 1:46 PM, Michael Catanzaro 
<mcatanzaro at igalia.com> wrote:
> CVE-2018-4118
>     Versions affected: WebKitGTK+ before 2.18.1.
>     Credit to Jun Kokatsu (@shhnjk).
>     Impact: Processing maliciously crafted web content may lead to
>     arbitrary code execution. Description: Multiple memory corruption
>     issues were addressed with improved memory handling.

The versions affected for CVE-2018-4118 was not correct. An attempt to 
fix this issue was included in 2.18.1, but the change was incomplete. 
This should have read:

Versions affected: WebKitGTK+ before 2.20.0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.webkit.org/pipermail/webkit-gtk/attachments/20180404/80507948/attachment.html>

More information about the webkit-gtk mailing list