CVE-2015-1153
Publication date 7 May 2015
Last updated 24 July 2024
Ubuntu priority
WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2015-1152 and CVE-2015-1154.
Status
Package | Ubuntu Release | Status |
---|---|---|
qtwebkit-opensource-src | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
qtwebkit-source | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
webkit | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
webkitgtk | ||
16.04 LTS xenial |
Fixed 2.4.10-0ubuntu1
|
|
14.04 LTS trusty |
Fixed 2.4.10-0ubuntu0.14.04.1
|
|
Notes
jdstrand
webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
References
Related Ubuntu Security Notices (USN)
- USN-2937-1
- WebKitGTK+ vulnerabilities
- 21 March 2016