CVE-2017-1000121 Information
Feb 19, 2026
cve
Description
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
Vulnerability Type (CWE)
CWE-190
Published
2017-11-01
Last Modified
2017-11-21
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
9.8 CRITICAL
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
References
http://trac.webkit.org/changeset/217126/webkit (Third Party Advisory) https://webkitgtk.org/security/WSA-2017-0007.html (Vendor Advisory)
Share on: