CVE-2020-13543: Use After Free
A code execution vulnerability exists in the WebSocket functionality of Webkit WebKitGTK 2.30.0. A specially crafted web page can trigger a use-after-free vulnerability which can lead to remote code execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Other sources
A flaw was found in WebKitGTK. Processing maliciously crafted web content may lead to arbitrary code execution.
— Red Hat
Webkit WebKitGTK could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the WebSocket functionality. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code or cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-13543.
What is the severity of CVE-2020-13543?
The severity of CVE-2020-13543 is high with a CVSS score of 8.8.
Which software is affected by CVE-2020-13543?
IBM Cloud Pak for Security (CP4S) version up to 1.7.2.0 and WebKitGTK version 2.30.0 are affected by CVE-2020-13543.
How does CVE-2020-13543 work?
CVE-2020-13543 is a code execution vulnerability that occurs in the WebSocket functionality of WebKit WebKitGTK due to a use-after-free issue. An attacker can exploit this vulnerability by convincing a user to visit a malicious website.
Are there any references for CVE-2020-13543?
Yes, you can find references for CVE-2020-13543 at the following links: IBM X-Force Exchange - https://exchange.xforce.ibmcloud.com/vulnerabilities/192461, IBM Support Page - https://www.ibm.com/support/pages/node/6493729, Gentoo Security Advisory - https://security.gentoo.org/glsa/202012-10.