685
VMScore

CVE-2019-6215

Published: 05/03/2019 Updated: 24/08/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A type confusion issue has been found in WebKitGTK+ prior to 2.22.6, where processing maliciously crafted web content may lead to arbitrary code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple iphone os

apple tvos

apple watchos

apple safari

apple icloud

apple itunes

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

Vendor Advisories

Several security issues were fixed in WebKitGTK+ ...
A type confusion issue has been found in WebKitGTK+ before 2226, where processing maliciously crafted web content may lead to arbitrary code execution ...

Exploits

/* githubcom/WebKit/webkit/blob/3fff8c40c665a09de5e3ede46fc35908f69353c3/Source/JavaScriptCore/runtime/Lookuph#L392 if (valueattributes() & PropertyAttribute::PropertyCallback) { JSValue result = valuelazyPropertyCallback()(vm, &thisObj); thisObjputDirect(vm, propertyName, result, attributesForStructure(val ...
WebKit JSC has an issue where reifyStaticProperty needs to set the PropertyAttribute::CustomAccessor flag for CustomGetterSetter ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-1-24-1 iTunes 1293 for Windows <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Prod ...