Related Vulnerabilities: CVE-2016-9643  

The regex code in WebKitGTK+ before 2.14.6 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).

Severity Medium

Remote Yes

Type Denial of service

Description

The regex code in WebKitGTK+ before 2.14.6 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis).

AVG-234 webkitgtk, webkitgtk2 2.4.11-6 Critical Unknown

AVG-235 webkit2gtk 2.14.5-1 2.16.1-1 Critical Fixed

28 Apr 2017 ASA-201704-9 AVG-235 webkit2gtk Critical multiple issues

https://webkitgtk.org/security/WSA-2017-0003.html