VDB
BDU%3A2023-06499
BDU%3A2023-06499
PUBLISHED
CVSS 10 CRITICAL
Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, вызванная переполнением буфера, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Apple Inc. | Red Hat Enterprise Linux, Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), tvOS, watchOS, iPadOS, iOS, WPE WebKit, WebKitGTK, MacOS |
Timeline
- Oct 10, 2023 CVE Published
- Apr 27, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
References
- https://www.debian.org/security/2023/dsa-5468 url
- http://www.openwall.com/lists/oss-security/2023/08/02/1 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/ url
- https://support.apple.com/en-us/HT213848 url
- https://support.apple.com/en-us/HT213843 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJ4DG5LHWG2INDOTPB7MO4JVJN6LKL3M/ url
- https://security-tracker.debian.org/tracker/CVE-2023-38592 url
- https://access.redhat.com/security/cve/cve-2023-38592 url
- https://webkitgtk.org/security/WSA-2023-0007.html advisory
- https://support.apple.com/en-us/HT213846 advisory
- https://support.apple.com/en-us/HT213841 advisory
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2023-1023SE17 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-0416SE47 advisory