WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.
{
"binaries": [
{
"binary_name": "libqt5webkit5",
"binary_version": "5.5.1+dfsg-2ubuntu1"
},
{
"binary_name": "libqt5webkit5-qmlwebkitplugin",
"binary_version": "5.5.1+dfsg-2ubuntu1"
},
{
"binary_name": "qml-module-qtwebkit",
"binary_version": "5.5.1+dfsg-2ubuntu1"
},
{
"binary_name": "qtwebkit5-doc-html",
"binary_version": "5.5.1+dfsg-2ubuntu1"
}
]
}