HIGH · 8.8

CVE-2023-2203

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web c...

Vulnerability Description

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WebkitgtkWebkit2Gtk32.38.5-1.el8
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.8
RedhatEnterprise Linux Server Aus8.8
RedhatEnterprise Linux Server Tus8.8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-2203?

CVE-2023-2203 is a vulnerability with a CVSS score of 8.8 (HIGH). A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web c...

How severe is CVE-2023-2203?

CVE-2023-2203 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-2203?

Check the references section above for vendor advisories and patch information. Affected products include: Webkitgtk Webkit2Gtk3, Redhat Enterprise Linux, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Server Tus.