Improper input validation in WebKitGTK+ - CVE-2018-11646
Published: August 10, 2018 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to mishandling of an unset pageURL in webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp. A remote attacker can send specially crafted input and cause the service to crash.
Affected software
Gentoo Linux
Opensuse
Fedora
webkitgtk4
webkit2gtk3
How to mitigate CVE-2018-11646
webkitgtk4 - update to 2.20.3-1.fc27
webkit2gtk3 - update to 2.20.3-1.fc28