runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.
{
"binaries": [
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "libqt5webkit5"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "libqt5webkit5-qmlwebkitplugin"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "qml-module-qtwebkit"
},
{
"binary_version": "5.5.1+dfsg-2ubuntu1",
"binary_name": "qtwebkit5-doc-html"
}
]
}