The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 14 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-14T19:53:43.151Z
Reserved: 2017-11-01T00:00:00Z
Link: CVE-2017-1000121
Updated: 2024-08-05T21:53:06.809Z
Status : Deferred
Published: 2017-11-01T21:29:00.280
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-1000121
No data.
OpenCVE Enrichment
No data.
Weaknesses