Risk | High |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2017-2373 |
CWE-ID | CWE-119 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software |
webkit2gtk (Alpine package) Operating systems & Components / Operating system package or component |
Vendor | Alpine Linux Development Team |
Security Bulletin
This security bulletin contains one high risk vulnerability.
EUVDB-ID: #VU33458
Risk: High
CVSSv4.0: 7.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Amber]
CVE-ID: CVE-2017-2373
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: Yes
DescriptionThe vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
MitigationInstall update from vendor's website.
Vulnerable software versionswebkit2gtk (Alpine package): 2.14.2-r0 - 2.14.3-r0
CPE2.3https://git.alpinelinux.org/aports/commit/?id=ae4a15801816b7f140076fa8f636d46247902af3
https://git.alpinelinux.org/aports/commit/?id=ccc2f318230304c6b8f9e6c8bafd85ad60077c32
https://git.alpinelinux.org/aports/commit/?id=9333b6b69da075f380935e8a636fb1cd817bf74d
https://git.alpinelinux.org/aports/commit/?id=e6cdfd728202da0c5ab2be4e3db99b5010f85cce
https://git.alpinelinux.org/aports/commit/?id=9eedb1462483dddad2de55715f16558844a078c5
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.