CVE-2023-2203
moderate-risk
Published 2023-05-17
A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Do I need to act?
-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Products (9)
References (8)
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:2653
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:3108
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-2203
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2188543
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:2653
Third Party Advisory
https://access.redhat.com/errata/RHSA-2023:3108
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2023-2203
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2188543
45
/ 100
moderate-risk
Severity
30/34 · Critical
Exploitability
0/34 · Minimal
Exposure
15/34 · Moderate