Name | CVE-2020-13584 |
Description | An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more) |
References | DSA-4797-1 |
NVD severity | medium |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
webkit2gtk (PTS) | stretch | 2.18.6-1~deb9u1 | vulnerable |
buster | 2.28.4-1~deb10u1 | vulnerable | |
buster (security) | 2.30.4-1~deb10u1 | fixed | |
bullseye, sid | 2.30.4-1 | fixed | |
wpewebkit (PTS) | bullseye, sid | 2.30.4-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
webkit2gtk | source | buster | 2.30.3-1~deb10u1 | DSA-4797-1 | ||
webkit2gtk | source | (unstable) | 2.30.3-1 | |||
wpewebkit | source | (unstable) | 2.30.3-1 |
[stretch] - webkit2gtk <ignored> (Not covered by security support in stretch)
[jessie] - webkit2gtk <ignored> (Not covered by security support in jessie)
https://webkitgtk.org/security/WSA-2020-0008.html