CVE-2015-5788
Publication date 18 September 2015
Last updated 24 July 2024
Ubuntu priority
Description
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| qtwebkit-opensource-src | ||
| 16.04 LTS xenial | Ignored no update available | |
| 14.04 LTS trusty | Not in release | |
| qtwebkit-source | ||
| 16.04 LTS xenial | Ignored no update available | |
| 14.04 LTS trusty | Not in release | |
| webkit | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| webkitgtk | ||
| 16.04 LTS xenial |
Fixed 2.4.10-0ubuntu1
|
|
| 14.04 LTS trusty |
Fixed 2.4.10-0ubuntu0.14.04.1
|
|
Notes
jdstrand
webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
References
Related Ubuntu Security Notices (USN)
- USN-2937-1
- WebKitGTK+ vulnerabilities
- 21 March 2016