CVE-2023-39434
Summary
| CVE | CVE-2023-39434 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-27 15:18:00 UTC |
| Updated | 2024-01-31 15:15:00 UTC |
| Description | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Processing web content may lead to arbitrary code execution. |
Risk And Classification
Problem Types: CWE-416
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: APPLE-SA-09-26-2023-2 macOS Sonoma 14 | MISC | seclists.org | |
| WebKitGTK+: Multiple Vulnerabilities (GLSA 202401-33) — Gentoo security | security.gentoo.org | ||
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2023-0009 | MISC | www.openwall.com | |
| Full Disclosure: APPLE-SA-09-26-2023-8 watchOS 10 | MISC | seclists.org | |
| About the security content of watchOS 10 - Apple Support | MISC | support.apple.com | |
| About the security content of iOS 17 and iPadOS 17 - Apple Support | MISC | support.apple.com | |
| Full Disclosure: APPLE-SA-09-26-2023-7 iOS 17 and iPadOS 17 | MISC | seclists.org | |
| About the security content of macOS Sonoma 14 - Apple Support | MISC | support.apple.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161084 Oracle Enterprise Linux Security Update for webkit2gtk3 (ELSA-2023-6535)
- 161167 Oracle Enterprise Linux Security Update for webkit2gtk3 (ELSA-2023-7055)
- 242303 Red Hat Update for webkit2gtk3 (RHSA-2023:6535)
- 242457 Red Hat Update for webkit2gtk3 (RHSA-2023:7055)
- 357018 Amazon Linux Security Advisory for webkitgtk4 : ALAS2-2024-2427
- 6000203 Debian Security Update for webkit2gtk (DSA 5468-1)
- 610525 Apple iOS 17 and iPadOS 17 Security Update Missing (HT213938)
- 710848 Gentoo Linux WebKitGTK+ Multiple Vulnerabilities (GLSA 202401-33)
- 755164 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2023:4211-1)
- 755166 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2023:4209-1)
- 755202 SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2023:4294-1)
- 941362 AlmaLinux Security Update for webkit2gtk3 (ALSA-2023:6535)
- 941448 AlmaLinux Security Update for webkit2gtk3 (ALSA-2023:7055)