CVE-2022-30293
Published on: Not Yet Published
Last Modified on: 10/14/2022 11:25:00 AM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
- CVE-2022-30293 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 5.1 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | HIGH | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
security_advisories/webkitgtk-2.36.0 at master · ChijinZ/security_advisories · GitHub | github.com text/html |
![]() |
Debian -- Security Information -- DSA-5154-1 webkit2gtk | www.debian.org Depreciated Link text/html |
![]() |
WebKitGTK+: Multiple Vulnerabilities (GLSA 202208-39) — Gentoo security | security.gentoo.org text/html |
![]() |
oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2022-0005 | www.openwall.com text/html |
![]() |
Debian -- Security Information -- DSA-5155-1 wpewebkit | www.debian.org Depreciated Link text/html |
![]() |
Bug Access Denied | bugs.webkit.org text/html |
![]() |
Related QID Numbers
- 160217 Oracle Enterprise Linux Security Update for webkit2gtk3 (ELSA-2022-7704)
- 160305 Oracle Enterprise Linux Security Update for webkit2gtk3 (ELSA-2022-8054)
- 179342 Debian Security Update for wpewebkit (DSA 5155-1)
- 179343 Debian Security Update for webkit2gtk (DSA 5154-1)
- 184159 Debian Security Update for webkit2gtkwpewebkit (CVE-2022-30293)
- 240833 Red Hat Update for webkit2gtk3 (RHSA-2022:7704)
- 240910 Red Hat Update for webkit2gtk3 (RHSA-2022:8054)
- 355438 Amazon Linux Security Advisory for webkitgtk4 : ALAS2-2023-2088
- 502400 Alpine Linux Security Update for webkit2gtk
- 503081 Alpine Linux Security Update for webkit2gtk
- 710613 Gentoo Linux WebKitGTK+ Multiple Vulnerabilities (GLSA 202208-39)
- 752211 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:2030-1)
- 752232 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:2071-1)
- 752233 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:2072-1)
- 752239 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2022:2089-1)
- 940779 AlmaLinux Security Update for webkit2gtk3 (ALSA-2022:7704)
- 940844 AlmaLinux Security Update for webkit2gtk3 (ALSA-2022:8054)
- 960171 Rocky Linux Security Update for webkit2gtk3 (RLSA-2022:7704)
- 960649 Rocky Linux Security Update for webkit2gtk3 (RLSA-2022:8054)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Application | Webkitgtk | Webkitgtk | All | All | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-30293 : In WebKitGTK through 2.36.0 and WPE WebKit , there is a heap-based buffer overflow in WebCore::Te… twitter.com/i/web/status/1… | 2022-05-06 05:08:00 |
![]() |
Potentially Critical CVE Detected! CVE-2022-30293 In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-bas… twitter.com/i/web/status/1… | 2022-05-06 06:56:00 |
![]() |
CVE-2022-30293 In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::Text… twitter.com/i/web/status/1… | 2022-05-06 23:17:32 |
![]() |
CVE-2022-30293 | 2022-05-06 06:38:37 |