#VU14308 Improper input validation in WebKitGTK+ - CVE-2018-11646
Published: August 10, 2018 / Updated: June 17, 2021
WebKitGTK+
WebKitGTK
Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to mishandling of an unset pageURL in webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp. A remote attacker can send specially crafted input and cause the service to crash.