Information disclosure in webkit2gtk (Alpine package)



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-2350
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
webkit2gtk (Alpine package)
Operating systems & Components / Operating system package or component

Vendor Alpine Linux Development Team

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU33470

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-2350

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.

Mitigation

Install update from vendor's website.

Vulnerable software versions

webkit2gtk (Alpine package): 2.14.2-r0 - 2.14.3-r0

CPE2.3 External links

http://git.alpinelinux.org/aports/commit/?id=ccc2f318230304c6b8f9e6c8bafd85ad60077c32
http://git.alpinelinux.org/aports/commit/?id=9333b6b69da075f380935e8a636fb1cd817bf74d
http://git.alpinelinux.org/aports/commit/?id=07f89546be5e1238d496d97d7cb453cc5c7a1e01
http://git.alpinelinux.org/aports/commit/?id=492988e0eece238d11f6dcec62a58c52b2740196
http://git.alpinelinux.org/aports/commit/?id=9eedb1462483dddad2de55715f16558844a078c5


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###