Bugzilla – Bug 1034856
VUL-0: CVE-2016-10222: webkitgtk: runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in SafariTechnology Preview Rele...
Last modified: 2020-06-29 06:28:37 UTC
CVE-2016-10222 runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-10222 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-10222.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10222 http://trac.webkit.org/changeset/208123 https://bugs.webkit.org/show_bug.cgi?id=164123
Federico is working on a webkit update. Federico - can you drive this also...