Out-of-bounds write in WebKitGTK+ and WPE WebKit - CVE-2020-9983

 

Out-of-bounds write in WebKitGTK+ and WPE WebKit - CVE-2020-9983

Published: September 18, 2020 / Updated: November 24, 2020


Vulnerability identifier: #VU46804
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9983
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in WebKit component in Apple Safari. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

WebKitGTK+
WPE WebKit
Gentoo Linux
Arch Linux
Red Hat CodeReady Linux Builder for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Ubuntu
Fedora
accountsservice (Red Hat package)
vala (Red Hat package)
gvfs (Red Hat package)
gjs (Red Hat package)
webkit2gtk3 (Red Hat package)
webkit2gtk (Debian package)
webkit2gtk (Alpine package)
glib2 (Red Hat package)
nautilus (Red Hat package)
gnome-online-accounts (Red Hat package)
gnome-control-center (Red Hat package)
gnome-terminal (Red Hat package)
gdm (Red Hat package)
gnome-boxes (Red Hat package)
gnome-software (Red Hat package)
gnome-settings-daemon (Red Hat package)
gnome-shell-extensions (Red Hat package)
gnome-shell (Red Hat package)
mutter (Red Hat package)
chrome-gnome-shell (Red Hat package)
libepubgen (Red Hat package)
gamin (Red Hat package)
libvisual (Red Hat package)
dleyna-server (Red Hat package)
dleyna-core (Red Hat package)
woff2 (Red Hat package)
cairomm (Red Hat package)
gtk-doc (Red Hat package)
soundtouch (Red Hat package)
OpenEXR (Red Hat package)
enchant2 (Red Hat package)
geoclue2 (Red Hat package)
20 (Red Hat package)
atkmm (Red Hat package)
gtkmm24 (Red Hat package)
gtk2 (Red Hat package)
libwebkit2gtk-4.0-37 (Ubuntu package)
libjavascriptcoregtk-4.0-18 (Ubuntu package)
webkit2gtk3
typelib-1_0-WebKit2WebExtension-4_0
webkit2gtk-4_0-injected-bundles
typelib-1_0-WebKit2-4_0
typelib-1_0-JavaScriptCore-4_0
webkit2gtk-4_0-injected-bundles-debuginfo
webkit2gtk3-debugsource
libwebkit2gtk3-lang
webkit2gtk3-devel
libwebkit2gtk-4_0-37-debuginfo
libjavascriptcoregtk-4_0-18
libjavascriptcoregtk-4_0-18-debuginfo
libwebkit2gtk-4_0-37
pangomm (Red Hat package)
webkitgtk4 (Red Hat package)
glibmm24 (Red Hat package)
libsass (Red Hat package)
gtkmm30 (Red Hat package)
geocode-glib (Red Hat package)
gnome-photos (Red Hat package)
libdazzle (Red Hat package)
Cloud Pak for Security (CP4S)
Apple Safari
Web Terminal
OpenShift Virtualization

How to mitigate CVE-2020-9983

Install updates from vendor's website.

WebKitGTK+ - update to 2.30.3
WPE WebKit - update to 2.30.3
accountsservice (Red Hat package) - update to 0.6.55-1.el8
vala (Red Hat package) - update to 0.40.19-2.el8
Cloud Pak for Security (CP4S) - update to 1.8.0.0
gvfs (Red Hat package) - update to 1.36.2-11.el8
gjs (Red Hat package) - update to 1.56.2-5.el8
webkit2gtk3 (Red Hat package) - update to 2.30.4-1.el8
webkit2gtk (Debian package) - update to 2.30.3-1~deb10u1
webkit2gtk (Alpine package) - update to 2.32.0-r0
glib2 (Red Hat package) - update to 2.56.4-9.el8
nautilus (Red Hat package) - update to 3.28.1-15.el8
gnome-online-accounts (Red Hat package) - update to 3.28.2-2.el8
gnome-control-center (Red Hat package) - update to 3.28.2-27.el8
gnome-terminal (Red Hat package) - update to 3.28.3-3.el8
gdm (Red Hat package) - update to 3.28.3-39.el8
gnome-boxes (Red Hat package) - update to 3.36.5-8.el8
gnome-software (Red Hat package) - update to 3.36.1-5.el8
gnome-settings-daemon (Red Hat package) - update to 3.32.0-14.el8
gnome-shell-extensions (Red Hat package) - update to 3.32.1-14.el8
gnome-shell (Red Hat package) - update to 3.32.2-30.el8
mutter (Red Hat package) - update to 3.32.2-57.el8
Apple Safari - update to 14.0
chrome-gnome-shell (Red Hat package) - update to 10.1-7.el8
libepubgen (Red Hat package) - update to 0.1.0-3.el8
gamin (Red Hat package) - update to 0.1.10-32.el8
libvisual (Red Hat package) - update to 0.4.0-25.el8
dleyna-server (Red Hat package) - update to 0.6.0-3.el8
dleyna-core (Red Hat package) - update to 0.6.0-3.el8
woff2 (Red Hat package) - update to 1.0.2-5.el8
Web Terminal - update to 1.3
cairomm (Red Hat package) - update to 1.12.0-8.el8
gtk-doc (Red Hat package) - update to 1.28-3.el8
soundtouch (Red Hat package) - update to 2.0.0-3.el8
OpenEXR (Red Hat package) - update to 2.2.0-12.el8
enchant2 (Red Hat package) - update to 2.2.3-3.el8
geoclue2 (Red Hat package) - update to 2.5.5-2.el8
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0
20 (Red Hat package) - update to 2.10.0-6.el8
atkmm (Red Hat package) - update to 2.24.2-7.el8
gtkmm24 (Red Hat package) - update to 2.24.5-6.el8
gtk2 (Red Hat package) - update to 2.24.32-5.el8
libwebkit2gtk-4.0-37 (Ubuntu package) - addressed in versions 2.30.3-0ubuntu0.18.04.1, 2.30.3-0ubuntu0.20.04.1, 2.30.3-0ubuntu0.20.10.1
libjavascriptcoregtk-4.0-18 (Ubuntu package) - addressed in versions 2.30.3-0ubuntu0.18.04.1, 2.30.3-0ubuntu0.20.04.1, 2.30.3-0ubuntu0.20.10.1
webkit2gtk3 - addressed in versions 2.30.3-1.fc32, 2.30.3-1.fc33
typelib-1_0-WebKit2WebExtension-4_0 - update to 2.32.1-2.63.3
webkit2gtk-4_0-injected-bundles - update to 2.32.1-2.63.3
typelib-1_0-WebKit2-4_0 - update to 2.32.1-2.63.3
typelib-1_0-JavaScriptCore-4_0 - update to 2.32.1-2.63.3
webkit2gtk-4_0-injected-bundles-debuginfo - update to 2.32.1-2.63.3
webkit2gtk3-debugsource - update to 2.32.1-2.63.3
libwebkit2gtk3-lang - update to 2.32.1-2.63.3
webkit2gtk3-devel - update to 2.32.1-2.63.3
libwebkit2gtk-4_0-37-debuginfo - update to 2.32.1-2.63.3
libjavascriptcoregtk-4_0-18 - update to 2.32.1-2.63.3
libjavascriptcoregtk-4_0-18-debuginfo - update to 2.32.1-2.63.3
libwebkit2gtk-4_0-37 - update to 2.32.1-2.63.3
pangomm (Red Hat package) - update to 2.40.1-6.el8
webkitgtk4 (Red Hat package) - update to 2.48.3-2.el7_9
glibmm24 (Red Hat package) - update to 2.56.0-2.el8
libsass (Red Hat package) - update to 3.4.5-6.el8
gtkmm30 (Red Hat package) - update to 3.22.2-3.el8
geocode-glib (Red Hat package) - update to 3.26.0-3.el8
gnome-photos (Red Hat package) - update to 3.28.1-4.el8
libdazzle (Red Hat package) - update to 3.28.5-2.el8

External References

Related Security Bulletins