CVE-2020-13543 PUBLISHED

A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.

EPSS 1.50% · 81.0th percentile

Risk Scores

EPSS Score
1.50%
81.0th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSqtwebkit-opensource-src5.212.0~alpha4-14build1, 5.212.0~alpha4-14, 5.212.0~alpha4-13
Ubuntu:20.04:LTSwpewebkit0, 2.28.0-1, 2.28.1-1
Ubuntu:18.04:LTSqtwebkit-source0, 2.3.2-0ubuntu13
Ubuntu:20.04:LTSqtwebkit-opensource-src5.212.0~alpha4-1ubuntu2.1, 0, 5.212.0~alpha3-3
Ubuntu:24.04:LTSqtwebkit-opensource-src0, 5.212.0~alpha4-33, 5.212.0~alpha4-33build1
Ubuntu:18.04:LTSqtwebkit-opensource-src5.9.1+dfsg-5ubuntu3, 5.9.1+dfsg-5ubuntu1, 0
Ubuntu:22.04:LTSwpewebkit2.34.1-1, 2.34.2-1, 2.34.3-1
Ubuntu:16.04:LTSqtwebkit-source0, 2.3.2-0ubuntu11, 2.3.2-0ubuntu10
Ubuntu:20.04:LTSwebkit2gtk2.26.2-1, 2.26.1-3, 0
Ubuntu:16.04:LTSqtwebkit-opensource-src0, 5.4.2+dfsg-1ubuntu2.1, 5.5.1+dfsg-2ubuntu1
Ubuntu:18.04:LTSwebkit2gtk2.28.0-0ubuntu0.18.04.3, 2.28.1-0ubuntu0.18.04.1, 2.28.2-0ubuntu0.18.04.1
Ubuntu:16.04:LTSwebkit2gtk2.10.4+dfsg1-1, 2.10.3+dfsg1-1, 2.8.5+dfsg1-3
Ubuntu:18.04:LTSwebkitgtk2.4.11-3ubuntu2, 2.4.11-3ubuntu3, 0
Ubuntu:16.04:LTSwebkitgtk2.4.11-0ubuntu0.1, 2.4.10-0ubuntu1, 2.4.9-2ubuntu2

Timeline

References

Open in Interactive Console →