Lucene search

K
cvelistRedhatCVELIST:CVE-2023-2203
HistoryMay 17, 2023 - 12:00 a.m.

CVE-2023-2203

2023-05-1700:00:00
CWE-416
redhat
www.cve.org
5
flaw
webkitgtk
use-after-free
vulnerability
input validation
denial of service
arbitrary code execution
network access
cve-2023-28205
security regression
red hat enterprise linux 8.8
red hat enterprise linux 9.2

AI Score

9.1

Confidence

High

EPSS

0.003

Percentile

71.3%

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "WebKitGTK",
    "versions": [
      {
        "version": "Affects webkit2gtk3 v2.38.5-1.el8 and webkit2gtk3 v2.38.5-1.el9, Fixed in webkit2gtk3 v2.38.5-1.el8_8.3 and webkit2gtk3 v2.38.5-1.el9_2.1",
        "status": "affected"
      }
    ]
  }
]