CVE-2015-5828

Publication date 9 October 2015

Last updated 24 July 2024


Ubuntu priority

The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.

Read the notes from the security team

Status

Package Ubuntu Release Status
qtwebkit-opensource-src 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
qtwebkit-source 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Ignored end of life
webkit 16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Ignored end of life
webkitgtk 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Notes


jdstrand

webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8