CVE-2020-13543

Name
CVE-2020-13543
Description
A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://talosintelligence.com/vulnerability_reports/TALOS-2020-1155
GENTOO https://security.gentoo.org/glsa/202012-10
MISC https://www.oracle.com/security-alerts/cpuapr2022.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:webkitgtk:webkitgtk:2.30.0:*:*:*:*:*:*:* webkitgtk == None == 2.30.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status