Wind River Support Network

HomeDefectsLIN10-4222
Not to be fixed

LIN10-4222 : Security Advisory - webkitgtk - CVE-2018-12293

Created: Jun 28, 2018    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in WebKitGTK+ prior to version 2.20.3 and WPE WebKit prior to version 2.20.1, is vulnerable to a heap-based buffer overflow triggered by an integer overflow, which could be abused by crafted HTML content.

https://nvd.nist.gov/vuln/detail/CVE-2018-12293

CVEs


Live chat
Online