CVE-2016-9643
published 2017-03-07CVE-2016-9643: The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open…
PriorityP432high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
0.92%
76.3th percentile
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | safari | — | — |
| apple | tvos | — | — |
| apple | watchos | — | — |
| webkit | webkit | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
Ubuntu
WebKitGTK+ vulnerabilities
vendor_ubuntu·2017-04-10
CVE-2016-9642 WebKitGTK+ vulnerabilities
Title: WebKitGTK+ vulnerabilities
Summary: Several security issues were fixed in WebKitGTK+.
A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
Apple
CVE-2016-9643: watchOS 3.2
vendor_apple·2017-03-27·CVSS 7.5
CVE-2016-9643 [HIGH] CVE-2016-9643: watchOS 3.2
Apple Security Update: About the security content of watchOS 3.2
Product: watchOS
Version: 3.2
CVE: CVE-2016-9643
Component: WebKit
Impact: Processing maliciously crafted web content may lead to high memory consumption
Description: An uncontrolled resource consumption issue was addressed through improved regex processing.
Apple
CVE-2016-9643: iOS 10.3
vendor_apple·2017-03-27·CVSS 7.5
CVE-2016-9643 [HIGH] CVE-2016-9643: iOS 10.3
Apple Security Update: About the security content of iOS 10.3
Product: iOS
Version: 10.3
CVE: CVE-2016-9643
Component: WebKit
Impact: Processing maliciously crafted web content may lead to high memory consumption
Description: An uncontrolled resource consumption issue was addressed through improved regex processing.
Apple
CVE-2016-9643: Safari 10.1
vendor_apple·2017-03-27·CVSS 7.5
CVE-2016-9643 [HIGH] CVE-2016-9643: Safari 10.1
Apple Security Update: About the security content of Safari 10.1
Product: Safari
Version: 10.1
CVE: CVE-2016-9643
Component: WebKit
Impact: Processing maliciously crafted web content may lead to high memory consumption
Description: An uncontrolled resource consumption issue was addressed through improved regex processing.
Apple
CVE-2016-9643: tvOS 10.2
vendor_apple·2017-03-27·CVSS 7.5
CVE-2016-9643 [HIGH] CVE-2016-9643: tvOS 10.2
Apple Security Update: About the security content of tvOS 10.2
Product: tvOS
Version: 10.2
CVE: CVE-2016-9643
Component: WebKit
Impact: Processing maliciously crafted web content may lead to high memory consumption
Description: An uncontrolled resource consumption issue was addressed through improved regex processing.
GHSA
GHSA-4mcp-j554-p27j: The regex code in Webkit 2
ghsa_unreviewed·2022-05-17
CVE-2016-9643 [HIGH] CWE-400 GHSA-4mcp-j554-p27j: The regex code in Webkit 2
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).
OSV
CVE-2016-9643: The regex code in Webkit 2
osv·2017-03-07·CVSS 7.5
CVE-2016-9643 [HIGH] CVE-2016-9643: The regex code in Webkit 2
The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2016/11/26/2http://www.openwall.com/lists/oss-security/2016/11/26/5http://www.securityfocus.com/bid/94559http://www.securitytracker.com/id/1038137https://security.gentoo.org/glsa/201706-15http://www.openwall.com/lists/oss-security/2016/11/26/2http://www.openwall.com/lists/oss-security/2016/11/26/5http://www.securityfocus.com/bid/94559http://www.securitytracker.com/id/1038137https://security.gentoo.org/glsa/201706-15
2017-03-07
Published