vendor:
WebKitGTK+
by:
Dhiraj Mishra
7.5
CVSS
HIGH
Crash
787
CWE
Product Name: WebKitGTK+
Affected Version From: WebKitGTK+ < 2.21.3
Affected Version To: WebKitGTK+ < 2.21.3
Patch Exists: YES
Related CWE: CVE-2018-11646
CPE: a:webkitgtk:webkitgtk
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/http/webkitplus, https://www.infosecmatter.com/nessus-plugin-library/?id=111626, https://www.infosecmatter.com/nessus-plugin-library/?id=112078, https://www.infosecmatter.com/nessus-plugin-library/?id=118453, https://www.infosecmatter.com/metasploit-auxiliary-modules-detailed-spreadsheet/
Platforms Tested: Fedora 27
2018
WebKitGTK+ < 2.21.3 - Crash (PoC)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unset pageURL, leading to an application crash.
Mitigation:
Upgrade to WebKitGTK+ version 2.21.4 or later.