vendor:
WebKitGTK
by:
Fire30
7,5
CVSS
HIGH
WebKit Heap based BOF
119
CWE
Product Name: WebKitGTK
Affected Version From: 2.1.2
Affected Version To: 2.1.2
Patch Exists: YES
Related CWE: CVE-2014-1303
CPE: a:webkitgtk:webkitgtk
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2014
CVE-2014-1303 PoC for Linux
This repository demonstrates the WebKit heap based buffer overflow vulnerability (CVE-2014-1303) on Linux. Original exploit is written for Mac OS X and PS4 (PlayStation4). It contains an exploit.html file which triggers the vulnerability and jump to ROP chain, scripts/roputil.js which contains utilities for ROP building, scripts/syscall.js which contains syscall ROP chains, scripts/code.js which contains hard coded remote loader, loader/ which contains a simple remote loader written in C and loader/bin2js which converts binary to js variables (for loader).
Mitigation:
Update to the latest version of WebKitGTK