CVE-2020-10018

WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling.

Date published : 2020-03-02

https://www.debian.org/security/2020/dsa-4641

https://lists.fedoraproject.org/archives/list/[email protected]/message/DOR5LPL4UASVAR76EIHCL4O2KGDWGC6K/