CVE-2023-39928: Use After Free
A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to visit a malicious webpage to trigger this vulnerability.
Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-39928
Other sources
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
— Ubuntu
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-39928.
What is the severity of CVE-2023-39928?
The severity of CVE-2023-39928 is high with a severity value of 8.8.
Which software versions are affected by CVE-2023-39928?
The affected software versions are WebKitGTK 2.40.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by visiting a malicious web page that abuses the MediaRecorder API of the affected WebKit GStreamer-based ports to cause memory corruption and potentially execute arbitrary code.
How can I fix CVE-2023-39928?
To fix CVE-2023-39928, update the WebKitGTK software to version 2.42.1-0ubuntu0.22.04.1 (for Ubuntu) or version 2.42.1-1 (for Debian).