WebKit: out-of-bounds read in... CVE-2017-13784 CNNVD-201709-047

6.8 AV AC AU C I A
发布: 2017-11-13
修订: 2019-03-22

There is an out-of-bounds read security vulnerability in WebKit. The vulnerability was confirmed on ASan build of WebKit nightly. ### ASan log: ``` ================================================================= ==30436==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x606000560c48 at pc 0x00010c8f583a bp 0x7fff5c1a8e70 sp 0x7fff5c1a8e68 READ of size 4 at 0x606000560c48 thread T0 ==30436==WARNING: invalid path to external symbolizer! ==30436==WARNING: Failed to use and restart external symbolizer! #0 0x10c8f5839 in WebCore::SimpleLineLayout::RunResolver::Run::logicalLeft() const (/Users/projectzero/webkit/webkit/WebKitBuild/Release/WebCore.framework/Versions/A/WebCore:x86_64+0x2ba4839) #1 0x10c8fd2cb in WebCore::SimpleLineLayout::RunResolver::runForPoint(WebCore::LayoutPoint const&) const (/Users/projectzero/webkit/webkit/WebKitBuild/Release/WebCore.framework/Versions/A/WebCore:x86_64+0x2bac2cb) #2 0x10c8f533f in...

0%
当前有3条漏洞利用/PoC
当前有7条受影响产品信息