CVE-2023-2203

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:webkitgtk:webkit2gtk3:2.38.5-1.el8:*:*:*:*:*:*:*
cpe:2.3:a:webkitgtk:webkit2gtk3:2.38.5-1.el9:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2023:2653 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2023:2653 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2023:3108 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2023:3108 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2023-2203 - Third Party Advisory () https://access.redhat.com/security/cve/CVE-2023-2203 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2188543 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2188543 - Issue Tracking, Third Party Advisory

25 May 2023, 17:25

Type Values Removed Values Added
First Time Redhat enterprise Linux
Redhat
Redhat enterprise Linux Server Tus
Redhat enterprise Linux Server Aus
Webkitgtk webkit2gtk3
Redhat enterprise Linux Eus
Webkitgtk
References (MISC) https://access.redhat.com/security/cve/CVE-2023-2203 - (MISC) https://access.redhat.com/security/cve/CVE-2023-2203 - Third Party Advisory
References (MISC) https://access.redhat.com/errata/RHSA-2023:3108 - (MISC) https://access.redhat.com/errata/RHSA-2023:3108 - Third Party Advisory
References (MISC) https://access.redhat.com/errata/RHSA-2023:2653 - (MISC) https://access.redhat.com/errata/RHSA-2023:2653 - Third Party Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2188543 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2188543 - Issue Tracking, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:webkitgtk:webkit2gtk3:2.38.5-1.el8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
cpe:2.3:a:webkitgtk:webkit2gtk3:2.38.5-1.el9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
CWE CWE-416

17 May 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-17 22:15

Updated : 2025-01-22 20:15


NVD link : CVE-2023-2203

Mitre link : CVE-2023-2203

CVE.ORG link : CVE-2023-2203


JSON object : View

Products Affected

redhat

  • enterprise_linux_eus
  • enterprise_linux_server_tus
  • enterprise_linux_server_aus
  • enterprise_linux

webkitgtk

  • webkit2gtk3
CWE
CWE-416

Use After Free