CVE-2020-11793

CWE-416Use After Free8 documents8 sources
Severity
8.8HIGH
EPSS
0.8%
top 25.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 24

Description

A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

NVDwebkitgtk/webkitgtk< 2.28.1
NVDwpewebkit/wpe_webkit< 2.28.1
Debianwpewebkit< 2.28.1-1+3
Debianwebkit2gtk< 2.28.1-1+3
NVDopensuse/leap15.1

Also affects: Fedora 30, 31, 32, Ubuntu Linux 18.04, 19.10

🔴Vulnerability Details

3
GHSA
GHSA-9rmm-vmrf-4wgf: A use-after-free issue exists in WebKitGTK before 22022-05-24
OSV
CVE-2020-11793: A use-after-free issue exists in WebKitGTK before 22020-04-17
CVEList
CVE-2020-11793: A use-after-free issue exists in WebKitGTK before 22020-04-17

📋Vendor Advisories

3
Ubuntu
WebKitGTK+ vulnerability2020-04-20
Red Hat
webkitgtk: use-after-free via crafted web content2020-04-16
Debian
CVE-2020-11793: webkit2gtk - A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2...2020

💬Community

1
Bugzilla
CVE-2020-11793 webkitgtk: use-after-free via crafted web content2020-04-29