VDB
CVE-2019-8375
CVE-2019-8375
PUBLISHED
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
EPSS 15.98% · 94.9th percentile
Risk Scores
EPSS Score
15.98%
94.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | qtwebkit-source | 0, 2.3.2-0ubuntu11, 2.3.2-0ubuntu10 |
| Ubuntu:18.04:LTS | qtwebkit-source | 0, 2.3.2-0ubuntu13 |
| Ubuntu:16.04:LTS | webkit2gtk | 2.20.2-0ubuntu0.16.04.1, 2.20.1-0ubuntu0.16.04.1, 2.18.6-0ubuntu0.16.04.1 |
| Ubuntu:18.04:LTS | qtwebkit-opensource-src | *, 0, 5.9.1+dfsg-5ubuntu1 |
| Ubuntu:18.04:LTS | webkit2gtk | 2.22.4-0ubuntu0.18.04.1, 2.22.5-0ubuntu0.18.04.1, 2.22.6-0ubuntu0.18.04.1 |
| Ubuntu:22.04:LTS | qtwebkit-opensource-src | 0, *, * |
| Ubuntu:18.04:LTS | webkitgtk | 2.4.11-3ubuntu3, 2.4.11-3ubuntu2, 2.4.11-3 |
| Ubuntu:20.04:LTS | qtwebkit-opensource-src | *, *, * |
| Ubuntu:16.04:LTS | webkitgtk | 2.4.9-2ubuntu2, 2.4.10-0ubuntu1, 2.4.11-0ubuntu0.1 |
| Ubuntu:24.04:LTS | qtwebkit-opensource-src | 0, 5.212.0~alpha4-33build1, 5.212.0~alpha4-34 |
| Ubuntu:16.04:LTS | qtwebkit-opensource-src | 0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1 |
Exploit Intelligence
Timeline
- Feb 24, 2019 CVE Published
- Feb 28, 2019 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
- May 13, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-8375 third-party-advisory
- https://trac.webkit.org/changeset/241515/webkit third-party-advisory
- https://www.inputzero.io/2019/02/fuzzing-webkit.html third-party-advisory
- https://ubuntu.com/security/notices/USN-3948-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-8375 third-party-advisory