CVE-2023-41983: Buffer Overflow
Published Oct 25, 2023
·Updated
Automation. The issue was addressed with improved checks.
Credit
Adam M., JZ, an anonymous researcher, Linus Henze(Pinauten GmbH), inooo, Mickey Jin@@patch1t, Grzegorz Riegel, Talal Haj Bakry(Mysk Inc), Tommy Mysk@@mysk_co(Mysk Inc), Mingxuan Yang@@PPPF00L(360 Vulnerability Research Institute), happybabywu(360 Vulnerability Research Institute), Guang Gong(360 Vulnerability Research Institute), (360 Vulnerability Research Institute), Alex Renda, Bistrit Dahal, Cristian Dinca(Computer Science), Romania, Claire Houston, 이준성(Junsung Lee)(Cross Republic), Pedro Ribeiro@@pedrib1337(Agile Information Security), Vitor Pedreira@@0xvhp_(Agile Information Security), 이준성(Junsung Lee), Kacper Kwapisz@@KKKas_, Adis Alic, Yiğit Can YILMAZ@@yilmazcanyigit, Sam Lakmaker, Kirin@@Pwnrin(SecuRing), Wojciech Regula(SecuRing), (Computer Science), CVE-2023-42946, Ting Ding, James Mancz, Omar Shibli, Lorenzo Cavallaro, Harry Lewandowski, Abhay Kailasia@@abhay_kailasia(Lakshmi Narain College Of Technology Bhopal India), Csaba Fitzl@@theevilbit(Offensive Security), Michael (Biscuit) Thomas - @social.lol@@biscuit, Peter Nguyễn Vũ Hoàng@@peternguyen14(STAR Labs SG Pte), Tomi Tokics@@tomitokics(iTomsn0w), CVE-2023-42823, Zhipeng Huo@@R3dF09(Tencent Security Xuanwu Lab), Noah Roskin-Frazee, Pr
Affected Software
19 affected componentsFixes available
debian/webkit2gtk<=2.36.4-1~deb10u1, <=2.38.6-0+deb10u1, <=2.40.5-1~deb11u1
2.42.4-1~deb11u12.42.2-1~deb12u12.42.4-1~deb12u12.42.4-1
debian/wpewebkit<=2.38.6-1~deb11u1, <=2.38.6-1
2.42.4-1
Apple macOS Sonoma<14.1
14.1
Apple Safari<17.1
17.1
Apple iOS<17.1
17.1
Apple iPadOS<17.1
17.1
Apple iOS<16.7.2
16.7.2
Apple iPadOS<16.7.2
16.7.2
Apple Safari<17.1
Apple iPadOS<16.7.2
Apple iPadOS>=17.0<17.1
Apple iPhone OS<16.7.2
Apple iPhone OS>=17.0<17.1
Apple macOS>=14.0<14.1
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Event History
Oct 25, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionWeakness
Mar 25, 2024
Data Sourced
via Red Hat·05:24 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2023-41983?
CVE-2023-41983 is a vulnerability in the WebKit process model that could lead to a denial-of-service.
2
Which versions of macOS are affected by CVE-2023-41983?
The vulnerability affects macOS Sonoma up to version 14.1.
3
Which versions of Safari are affected by CVE-2023-41983?
Safari versions up to 17.1 are affected by this vulnerability.
4
Which versions of iOS are affected by CVE-2023-41983?
iOS versions up to 16.7.2 and 17.1 are affected by this vulnerability.
5
What is the remedy for CVE-2023-41983?
The vulnerability is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1.