CVE-2023-2203
published 2023-05-17CVE-2023-2203: A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with…
PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.93%
57.1th percentile
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | webkit2gtk | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| webkitgtk | webkit2gtk3 | — | — |
| webkitgtk | webkit2gtk3 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Citrix
Citrix StoreFront Security Bulletin for CVE-2023-5914
vendor_citrix·2024-01-16·CVSS 6.1
CVE-2023-5914 [MEDIUM] CWE-79 Citrix StoreFront Security Bulletin for CVE-2023-5914
Citrix StoreFront Security Bulletin for CVE-2023-5914
Pre-requisites CWE CVE-2023-5914 Cross-site scripting (XSS) Requires victim to access an attacker-controlled link in the browser CWE-79 Instructions Cloud Software Group strongly urges affected customers of Citrix StoreFront to install the relevant updated versions of Citrix StoreFront as soon as possible: Current Release (CR) Citrix StoreFront 2308.1 and later Citrix StoreFront 2311and later Long Term Service Release (LTSR) Citrix StoreFront 1912 LTSR CU8 hotfix 3.22.8001.2* and later Citrix StoreFront 2203 LTSR CU4 Update 1 and later Please use the following link for downloading the builds: https://www.citrix.com/downloads/ *Citrix StoreFront 1912 LTSR CU8 hotfix 3.22.8001.2 is available to download at the following link: https://sup
Citrix
Citrix Session Recording Security Bulletin for CVE-2023-6184
vendor_citrix·2024-01-16·CVSS 7.2
CVE-2023-6184 [HIGH] CWE-913 Citrix Session Recording Security Bulletin for CVE-2023-6184
Citrix Session Recording Security Bulletin for CVE-2023-6184
Pre-requisites CWE CVE-2023-6184 An authenticated user can perform RCE Attacker must possess admin privileges to the Session Recording server CWE-913 Instructions Cloud Software Group strongly urges affected customers of Citrix Session Recording to install the relevant updated versions of Citrix Session Recording as soon their upgrade schedule permits: Current Release (CR) Citrix Virtual Apps and Desktops 2311 and later Long Term Service Release (LTSR) Citrix Virtual Apps and Desktops 1912 LTSR CU8 hotfix 19.12.8100.4* and later Citrix Virtual Apps and Desktops 2203 LTSR CU4 and later Please use the following link for downloading the builds: https://www.citrix.com/downloads/ * Citrix Virtual Apps and Desktops 1912 LTSR CU8 hotfi
Citrix
Windows and Linux Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2023-24490
vendor_citrix·2023-06-14·CVSS 4.3
CVE-2023-24490 [MEDIUM] CWE-284 Windows and Linux Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2023-24490
Windows and Linux Virtual Delivery Agent for CVAD and Citrix DaaS Security Bulletin CVE-2023-24490
Pre-requisites CWE CVE-2023-24490 Users with only access to launch VDA applications can launch an unauthorized desktop Authorized user with the ability to launch a virtual application CWE-284 Instructions Citrix strongly recommends that customers upgrade their Windows and Linux Virtual Delivery Agents to versions that contain the fixes as soon as possible. Windows Virtual Delivery Agent versions that contain the fixes are: Citrix Virtual Apps and Desktops 2305 and later versions Citrix Virtual Apps and Desktops 2203 LTSR CU3 and later cumulative updates Citrix Virtual Apps and Desktops 1912 LTSR CU7 and later cumulative updates Linux Virtual Delivery Agent versions that contain the fixes are
Red Hat
webkitgtk: Regression of CVE-2023-28205 fixes in the Red Hat Enterprise Linux
vendor_redhat·2023-05-09·CVSS 8.8
CVE-2023-2203 [HIGH] CWE-416 webkitgtk: Regression of CVE-2023-28205 fixes in the Red Hat Enterprise Linux
webkitgtk: Regression of CVE-2023-28205 fixes in the Red Hat Enterprise Linux
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists becaus
Debian
CVE-2023-2203: webkit2gtk - A flaw was found in the WebKitGTK package. An improper input validation issue ma...
vendor_debian·2023·CVSS 8.8
CVE-2023-2203 [HIGH] CVE-2023-2203: webkit2gtk - A flaw was found in the WebKitGTK package. An improper input validation issue ma...
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Citrix
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483
vendor_citrix·CVSS 7.8
CVE-2023-24483 [HIGH] CWE-269 Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483
Citrix Virtual Apps and Desktops Security Bulletin for CVE-2023-24483
Vulnerability Type Pre-conditions CVE-2023-24483 Privilege Escalation to NT AUTHORITY\SYSTEM on the vulnerable VDA CWE-269: Improper Privilege Management Local access to a Windows VDA as a standard Windows user The vulnerability affects the following supported versions of Citrix Virtual Apps and Desktops: Current Release (CR) Citrix Virtual Apps and Desktops versions before 2212 Long Term Service Release (LTSR) Citrix Virtual Apps and Desktops 2203 LTSR before CU2 Citrix Virtual Apps and Desktops 1912 LTSR before CU6 In addition, customers using Citrix Virtual Apps and Desktops Service using any of the vulnerable versions of Citrix Virtual Apps and Desktops Windows VDA are affected and need to take action. Instructions
GHSA
GHSA-p2w5-xch3-v6pv: A flaw was found in the WebKitGTK package
ghsa_unreviewed·2023-05-18·CVSS 8.8
CVE-2023-2203 [HIGH] CWE-416 GHSA-p2w5-xch3-v6pv: A flaw was found in the WebKitGTK package
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
OSV
CVE-2023-2203: A flaw was found in the WebKitGTK package
osv·2023-05-17·CVSS 8.8
CVE-2023-2203 [HIGH] CVE-2023-2203: A flaw was found in the WebKitGTK package
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:2653https://access.redhat.com/errata/RHSA-2023:3108https://access.redhat.com/security/cve/CVE-2023-2203https://bugzilla.redhat.com/show_bug.cgi?id=2188543https://access.redhat.com/errata/RHSA-2023:2653https://access.redhat.com/errata/RHSA-2023:3108https://access.redhat.com/security/cve/CVE-2023-2203https://bugzilla.redhat.com/show_bug.cgi?id=2188543
2023-05-17
Published