Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-2653

Опубликовано: 17 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-2653: webkit2gtk3 security update (IMPORTANT)

[2.38.5-1.1]

  • Add patch for CVE-2023-28205 Resolves: #2185745

[2.38.5-1]

  • Update to 2.38.5 Related: #2127467

[2.38.4-1]

  • Update to 2.38.4 Related: #2127467

[2.38.3-1]

  • Update to 2.38.3 Related: #2127467

[2.38.2-1]

  • Update to 2.38.2 Related: #2127467

[2.38.1-2]

  • Fix use with aarch64 64 KiB page size Related: #2127467

[2.38.1-1]

  • Update to 2.38.1 Resolves: #2127467

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

webkit2gtk3

2.38.5-1.el9

webkit2gtk3

2.38.5-1.el9_2.1

webkit2gtk3-devel

2.38.5-1.el9

webkit2gtk3-devel

2.38.5-1.el9_2.1

webkit2gtk3-jsc

2.38.5-1.el9

webkit2gtk3-jsc

2.38.5-1.el9_2.1

webkit2gtk3-jsc-devel

2.38.5-1.el9

webkit2gtk3-jsc-devel

2.38.5-1.el9_2.1

Oracle Linux x86_64

webkit2gtk3

2.38.5-1.el9

webkit2gtk3

2.38.5-1.el9_2.1

webkit2gtk3-devel

2.38.5-1.el9

webkit2gtk3-devel

2.38.5-1.el9_2.1

webkit2gtk3-jsc

2.38.5-1.el9

webkit2gtk3-jsc

2.38.5-1.el9_2.1

webkit2gtk3-jsc-devel

2.38.5-1.el9

webkit2gtk3-jsc-devel

2.38.5-1.el9_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
redhat
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
nvd
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
debian
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validatio ...

rocky
около 2 лет назад

Important: webkit2gtk3 security update