Memory corruption in webkit2gtk (Alpine package)



Published: 2017-12-26
Risk High
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-7157
CWE-ID CWE-119
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
webkit2gtk (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one high risk vulnerability.

1) Memory corruption

EUVDB-ID: #VU9667

Risk: High

CVSSv3.1: 8.3 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-7157

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to boundary error when handling malicious input. A remote attacker can trick the victim into loading a specially crafted web content, trigger memory corruption in the WebKit component and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability may result in system compromise.

Mitigation

Install update from vendor's website.

Vulnerable software versions

webkit2gtk (Alpine package): 2.18.3-r0

External links

http://git.alpinelinux.org/aports/commit/?id=ccc2f318230304c6b8f9e6c8bafd85ad60077c32
http://git.alpinelinux.org/aports/commit/?id=9333b6b69da075f380935e8a636fb1cd817bf74d
http://git.alpinelinux.org/aports/commit/?id=041fef015184af46bcc6eb6e421bdc5e3259c709
http://git.alpinelinux.org/aports/commit/?id=07f89546be5e1238d496d97d7cb453cc5c7a1e01
http://git.alpinelinux.org/aports/commit/?id=492988e0eece238d11f6dcec62a58c52b2740196


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###