CVE-2023-43010
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.
Security Fix(es):
- chromium-browser: Use after free in ANGLE (CVE-2024-4558)
- webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-40789)
- webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking (CVE-2024-40780)
- webkitgtk: webkit2gtk: Out-of-bounds read was addressed with improved bounds checking (CVE-2024-40779)
- webkitgtk: webkit2gtk: Use-after-free was addressed with improved memory management (CVE-2024-40782)
- webkitgtk: Visiting a malicious website may lead to address bar spoofing (CVE-2024-40866)
- webkitgtk: A malicious website may cause unexpected cross-origin behavior (CVE-2024-23271)
- webkitgtk: Processing web content may lead to arbitrary code execution (CVE-2024-27820)
- webkitgtk: A maliciously crafted webpage may be able to fingerprint the user (CVE-2024-27838)
- webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2024-27851)
- webkitgtk: A malicious website may exfiltrate data cross-origin (CVE-2024-44187)
- webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-44185)
- webkitgtk: webkit2gtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-44244)
- webkitgtk: webkit2gtk: Processing maliciously crafted web content may prevent Content Security Policy from being enforced (CVE-2024-44296)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2024:9636, https://access.redhat.com/security/cve/CVE-2023-42950, https://access.redhat.com/security/cve/CVE-2023-43010, https://access.redhat.com/security/cve/CVE-2024-23271, https://access.redhat.com/security/cve/CVE-2024-27820, https://access.redhat.com/security/cve/CVE-2024-27834, https://access.redhat.com/security/cve/CVE-2024-27838, https://access.redhat.com/security/cve/CVE-2024-27851, https://access.redhat.com/security/cve/CVE-2024-27856, https://access.redhat.com/security/cve/CVE-2024-40779, https://access.redhat.com/security/cve/CVE-2024-40780, https://access.redhat.com/security/cve/CVE-2024-40782, https://access.redhat.com/security/cve/CVE-2024-40789, https://access.redhat.com/security/cve/CVE-2024-40866, https://access.redhat.com/security/cve/CVE-2024-44185, https://access.redhat.com/security/cve/CVE-2024-44187, https://access.redhat.com/security/cve/CVE-2024-44244, https://access.redhat.com/security/cve/CVE-2024-44296, https://access.redhat.com/security/cve/CVE-2024-4558, https://access.redhat.com/security/cve/CVE-2024-54534, https://access.redhat.com/security/cve/CVE-2024-54658, https://access.redhat.com/security/cve/CVE-2025-43480
