CVE-2020-13584: Use After Free
A flaw was found in WebKitGTK. Processing maliciously crafted web content may lead to arbitrary code execution.
Reference: https://webkitgtk.org/security/WSA-2020-0008.html
Other sources
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.
Webkit WebKitGTK could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the ImageDecoderGStreamer functionality. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code or cause the application to crash.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13584?
CVE-2020-13584 is an exploitable use-after-free vulnerability in WebKitGTK browser version 2.30.1 x64.
How can a remote attacker exploit CVE-2020-13584?
A remote attacker can exploit CVE-2020-13584 by persuading a victim to visit a specially crafted website, allowing the attacker to execute arbitrary code or cause a denial-of-service condition.
What is the severity level of CVE-2020-13584?
CVE-2020-13584 has a severity level of high with a CVSS score of 8.8.
Which software versions are affected by CVE-2020-13584?
IBM Cloud Pak for Security (CP4S) versions 1.7.2.0, 1.7.1.0, and 1.7.0.0, WebKitGTK version 2.30.1 x64, and Fedora version 32 are affected by CVE-2020-13584.
How can I fix CVE-2020-13584?
To fix CVE-2020-13584, update your software to the recommended versions: WebKitGTK to version 2.42.1-2, deb packages wpewebkit to version 2.42.1-1, and webkit2gtk to version 2.42.1-2.