vendor:
WebKitFaviconDatabase
by:
Dhiraj Mishra, Hardik Mehta, Zubin Devnani, Manuel Caballero
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: WebKitFaviconDatabase
Affected Version From: < 2.21.3
Affected Version To: < 2.21.3
Patch Exists: YES
Related CWE: 2018-11646
CPE: 2.21.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' DoS
This module exploits a vulnerability in WebKitFaviconDatabase when pageURL is unset. If successful, it could lead to application crash, resulting in denial of service.
Mitigation:
Update to WebKitGTK+ version 2.21.3 or later