Bugzilla – Bug 1013715
VUL-1: CVE-2016-9642: webkitgtk,webkitgtk3: Heap read out-of-bounds parsing a Javascript file with the last revision ofJavaScript Core
Last modified: 2020-06-29 06:26:50 UTC
CVE-2016-9642 https://bugs.webkit.org/show_bug.cgi?id=164000 AddressSanitizer: heap-buffer-overflow READ of size 16 #0 0x7ffff67f04af in WTF::(anonymous namespace)::lockHashtable() (/home/g/Work/Code/webkit-master/WebKitBuild/Release/lib/libjavascriptcoregtk-4.0.so.18+0x20cc4af) #1 0x7ffff67f1b6c in WTF::ParkingLot::parkConditionallyImpl(void const*, WTF::ScopedLambda<bool ()> const&, WTF::ScopedLambda<void ()> const&, std::chrono::time_point<std::chrono::_V2::steady_clock, std::chrono::duration<long, std::ratio<1l, 1000000000l> > >) (/home/g/Work/Code/webkit-master/WebKitBuild/Release/lib/libjavascriptcoregtk-4.0.so.18+0x20cdb6c) #2 0x7ffff67cc1cb in std::_Function_handler<void (), WTF::AutomaticThread::start(WTF::Locker<WTF::LockBase> const&)::{lambda()#1}>::_M_invoke(std::_Any_data const&) (/home/g/Work/Code/webkit-master/WebKitBuild/Release/lib/libjavascriptcoregtk-4.0.so.18+0x20a81cb) After a month, i received no response from the original bug report in the webkit bug tracker. Additionally, Chrome / Chromium is not affected. Use CVE-2016-9642. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-9642 http://seclists.org/oss-sec/2016/q4/533 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-9642.html
bugbot adjusting priority