CVE-2013-7324
Published: 17 February 2020
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
Notes
| Author | Note |
|---|---|
| jdstrand | webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8 |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
webkit Launchpad, Ubuntu, Debian |
lucid |
Ignored
(reached end-of-life)
|
| precise |
Ignored
(no update available)
|
|
| quantal |
Ignored
(reached end-of-life)
|
|
| saucy |
Ignored
(reached end-of-life)
|
|
| trusty |
Does not exist
|
|
| upstream |
Needs triage
|
|
| utopic |
Does not exist
|
|
| vivid |
Does not exist
|
|
| wily |
Does not exist
|
|
| xenial |
Does not exist
|
|
| yakkety |
Does not exist
|
|
|
webkitgtk Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
| precise |
Does not exist
|
|
| quantal |
Does not exist
|
|
| saucy |
Does not exist
|
|
| trusty |
Does not exist
(trusty was not-affected [2.4.8-1ubuntu1~ubuntu14.04.1])
|
|
| upstream |
Needs triage
|
|
| utopic |
Ignored
(reached end-of-life)
|
|
| vivid |
Ignored
(reached end-of-life)
|
|
| wily |
Not vulnerable
(2.4.9-2ubuntu2)
|
|
| xenial |
Not vulnerable
(2.4.9-2ubuntu2)
|
|
| yakkety |
Not vulnerable
(2.4.9-2ubuntu2)
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 5.3 |
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | Low |
| Availability impact | None |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |