Buffer overflow - CVE-2016-4624

 

Buffer overflow - CVE-2016-4624

Published: July 22, 2016 / Updated: August 4, 2020


Vulnerability identifier: #VU33558
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4624
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.


Affected software

webkit2gtk (Alpine package)
webkitgtk4
Fedora

How to mitigate CVE-2016-4624

Install update from vendor's website.

webkit2gtk (Alpine package) - update to 2.12.5-r0
webkitgtk4 - addressed in versions 2.12.4-1.fc23, 2.12.4-1.fc24

External References

Related Security Bulletins