In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.36.0 | third party advisory exploit |
https://bugs.webkit.org/show_bug.cgi?id=237187 | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2022/05/30/1 | third party advisory mailing list |
https://www.debian.org/security/2022/dsa-5154 | third party advisory vendor advisory |
https://www.debian.org/security/2022/dsa-5155 | third party advisory vendor advisory |
https://security.gentoo.org/glsa/202208-39 | third party advisory vendor advisory |