The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
{
"binaries": [
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "libqt5webkit5"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "libqt5webkit5-dev"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "libqt5webkit5-qmlwebkitplugin"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "qml-module-qtwebkit"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "qtwebkit5-doc-html"
}
]
}{
"binaries": [
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "gir1.2-javascriptcoregtk-3.0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "gir1.2-webkit-3.0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "gir1.2-webkit2-3.0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libjavascriptcoregtk-1.0-0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libjavascriptcoregtk-1.0-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libjavascriptcoregtk-3.0-0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libjavascriptcoregtk-3.0-bin"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libjavascriptcoregtk-3.0-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkit-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkit2gtk-3.0-25"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkit2gtk-3.0-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-1.0-0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-1.0-common"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-3.0-0"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-3.0-common"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-3.0-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-common-dev"
},
{
"binary_version": "2.4.11-0ubuntu0.1",
"binary_name": "libwebkitgtk-dev"
}
]
}{
"binaries": [
{
"binary_version": "5.212.0~alpha2-7ubuntu1",
"binary_name": "libqt5webkit5"
},
{
"binary_version": "5.212.0~alpha2-7ubuntu1",
"binary_name": "libqt5webkit5-dev"
},
{
"binary_version": "5.212.0~alpha2-7ubuntu1",
"binary_name": "qml-module-qtwebkit"
},
{
"binary_version": "5.212.0~alpha2-7ubuntu1",
"binary_name": "qtwebkit5-doc-html"
}
]
}{
"binaries": [
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "gir1.2-javascriptcoregtk-3.0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "gir1.2-webkit-3.0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libjavascriptcoregtk-1.0-0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libjavascriptcoregtk-1.0-dev"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libjavascriptcoregtk-3.0-0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libjavascriptcoregtk-3.0-bin"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libjavascriptcoregtk-3.0-dev"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libwebkitgtk-1.0-0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libwebkitgtk-3.0-0"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libwebkitgtk-3.0-dev"
},
{
"binary_version": "2.4.11-3ubuntu3",
"binary_name": "libwebkitgtk-dev"
}
]
}