CVE-2023-41983
Published: 16 November 2023
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
Notes
Author | Note |
---|---|
jdstrand | webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8 |
mdeslaur | It is no longer possible to build new webkit2gtk versions on focal and earlier. Marking as ignored. |
Priority
Status
Package | Release | Status |
---|---|---|
webkitgtk Launchpad, Ubuntu, Debian |
trusty |
Ignored
(end of standard support)
|
xenial |
Needs triage
|
|
bionic |
Needs triage
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Needs triage
|
|
webkit2gtk Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
|
|
bionic |
Ignored
|
|
focal |
Ignored
|
|
upstream |
Released
(2.42.2)
|
|
jammy |
Released
(2.42.2-0ubuntu0.22.04.1)
|
|
lunar |
Released
(2.42.2-0ubuntu0.23.04.1)
|
|
mantic |
Released
(2.42.2-0ubuntu0.23.10.1)
|
|
qtwebkit-source Launchpad, Ubuntu, Debian |
trusty |
Ignored
(end of standard support)
|
xenial |
Needs triage
|
|
bionic |
Needs triage
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Needs triage
|
|
qtwebkit-opensource-src Launchpad, Ubuntu, Debian |
trusty |
Ignored
(end of standard support)
|
xenial |
Needs triage
|
|
bionic |
Needs triage
|
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
lunar |
Needs triage
|
|
mantic |
Needs triage
|
|
upstream |
Needs triage
|
|
wpewebkit Launchpad, Ubuntu, Debian |
trusty |
Ignored
(end of standard support)
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Needs triage
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |