Use-after-free in WPE WebKit and WebKitGTK+ - CVE-2020-10018
Published: March 13, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing web conftent. A remote attacker can trick a victim to visit a specially crafted web page, trigger use-after-free error and execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
WebKitGTK+
Gentoo Linux
Arch Linux
SUSE CaaS Platform
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise High Performance Computing
Opensuse
Fedora
Service Telemetry Framework
webkit2gtk (Ubuntu package)
webkit2gtk (Debian package)
webkit2gtk (Alpine package)
gnome-remote-desktop (Red Hat package)
pipewire0.2 (Red Hat package)
pipewire (Red Hat package)
webrtc-audio-processing (Red Hat package)
dleyna-renderer (Red Hat package)
LibRaw (Red Hat package)
vte291 (Red Hat package)
PackageKit (Red Hat package)
xdg-desktop-portal-gtk (Red Hat package)
xdg-desktop-portal (Red Hat package)
frei0r-plugins (Red Hat package)
potrace (Red Hat package)
gtk-doc (Red Hat package)
gvfs (Red Hat package)
tracker (Red Hat package)
webkit2gtk3
webkit2gtk3 (Red Hat package)
libwebkit2gtk3-lang
webkit2gtk3-debugsource
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2WebExtension-4_0
typelib-1_0-JavaScriptCore-4_0
libwebkit2gtk-4_0-37-debuginfo
libwebkit2gtk-4_0-37
libjavascriptcoregtk-4_0-18-debuginfo
webkit2gtk3-devel
typelib-1_0-WebKit2-4_0
libjavascriptcoregtk-4_0-18
libsoup (Red Hat package)
gtk3 (Red Hat package)
gnome-photos (Red Hat package)
gnome-session (Red Hat package)
nautilus (Red Hat package)
gnome-control-center (Red Hat package)
pygobject3 (Red Hat package)
gnome-terminal (Red Hat package)
gdm (Red Hat package)
gsettings-desktop-schemas (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2020-10018
webkit2gtk (Ubuntu package) - addressed in versions 2.28.0-0ubuntu0.18.04.3, 2.28.0-0ubuntu0.19.10.2
webkit2gtk (Debian package) - update to 2.26.4-1~deb10u2
webkit2gtk (Alpine package) - addressed in versions 2.28.0-r0, 2.28.0-r1
Quay - update to 3.3.3
gnome-remote-desktop (Red Hat package) - update to 0.1.8-3.el8
pipewire0.2 (Red Hat package) - update to 0.2.7-6.el8
pipewire (Red Hat package) - update to 0.3.6-1.el8
webrtc-audio-processing (Red Hat package) - update to 0.3-9.el8
dleyna-renderer (Red Hat package) - update to 0.6.0-3.el8
LibRaw (Red Hat package) - update to 0.19.5-2.el8
vte291 (Red Hat package) - update to 0.52.4-2.el8
PackageKit (Red Hat package) - update to 1.1.12-6.el8
xdg-desktop-portal-gtk (Red Hat package) - update to 1.6.0-1.el8
xdg-desktop-portal (Red Hat package) - update to 1.6.0-2.el8
frei0r-plugins (Red Hat package) - update to 1.6.1-7.el8
potrace (Red Hat package) - update to 1.15-3.el8
gtk-doc (Red Hat package) - update to 1.28-2.el8
gvfs (Red Hat package) - update to 1.36.2-10.el8
tracker (Red Hat package) - update to 2.1.5-2.el8
webkit2gtk3 - addressed in versions 2.28.0-2.fc32, 2.28.0-5.fc30, 2.28.0-6.fc31, 2.28.0-7.fc32
webkit2gtk3 (Red Hat package) - update to 2.28.4-1.el8
libwebkit2gtk3-lang - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
webkit2gtk3-debugsource - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
webkit2gtk-4_0-injected-bundles-debuginfo - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
webkit2gtk-4_0-injected-bundles - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
typelib-1_0-WebKit2WebExtension-4_0 - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
typelib-1_0-JavaScriptCore-4_0 - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
libwebkit2gtk-4_0-37-debuginfo - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
libwebkit2gtk-4_0-37 - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
libjavascriptcoregtk-4_0-18-debuginfo - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
webkit2gtk3-devel - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
typelib-1_0-WebKit2-4_0 - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
libjavascriptcoregtk-4_0-18 - addressed in versions 2.34.3-2.82.1, 2.34.3-3.92.1
libsoup (Red Hat package) - update to 2.62.3-2.el8
gtk3 (Red Hat package) - update to 3.22.30-6.el8
gnome-photos (Red Hat package) - update to 3.28.1-3.el8
gnome-session (Red Hat package) - update to 3.28.1-10.el8
nautilus (Red Hat package) - update to 3.28.1-14.el8
gnome-control-center (Red Hat package) - update to 3.28.2-22.el8
pygobject3 (Red Hat package) - update to 3.28.3-2.el8
gnome-terminal (Red Hat package) - update to 3.28.3-2.el8
gdm (Red Hat package) - update to 3.28.3-34.el8
gsettings-desktop-schemas (Red Hat package) - update to 3.32.0-5.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-11.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-11.el8
gnome-shell (Red Hat package) - update to 3.32.2-20.el8
mutter (Red Hat package) - update to 3.32.2-48.el8
External References
Related Security Bulletins
- Remote code execution in WebKitGTK and WPE WebKit
- Arch Linux update for webkit2gtk
- Debian update for webkit2gtk
- Ubuntu update for WebKitGTK+
- OpenSUSE Linux update for webkit2gtk3
- Use-after-free in webkit2gtk (Alpine package)
- Gentoo update for WebKitGTK+
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Red Hat Enterprise Linux 8 update for GNOME
- SUSE update for webkit2gtk3
- SUSE update for webkit2gtk3
- Fedora 32 update for webkit2gtk3
- Fedora 30 update for webkit2gtk3
- Fedora 31 update for webkit2gtk3
- Fedora 32 update for webkit2gtk3