CVE-2015-5825
Publication date 18 September 2015
Last updated 24 July 2024
Ubuntu priority
Description
WebKit in Apple iOS before 9 does not properly restrict the availability of Performance API times, which allows remote attackers to obtain sensitive information about the browser history, mouse movement, or network traffic via crafted JavaScript code.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| webkit | ||
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| qtwebkit-opensource-src | ||
| 16.04 LTS xenial | Ignored no update available | |
| 14.04 LTS trusty | Not in release | |
| qtwebkit-source | ||
| 16.04 LTS xenial | Ignored no update available | |
| 14.04 LTS trusty | Not in release | |
| webkitgtk | ||
| 16.04 LTS xenial | Ignored no update available | |
| 14.04 LTS trusty | Not in release | |
Notes
jdstrand
webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8