Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-3108

Опубликовано: 24 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-3108: webkit2gtk3 security update (IMPORTANT)

[2.38.5-1.3]

  • Restore libwpe and wpebackend-fdo dependencies Related: #2185741 (sort of)

[2.38.5-1.2]

  • Disable libwpe and wpebackend-fdo dependencies Related: #2185741 (sort of)

[2.38.5-1.1]

  • Add patch for CVE-2023-28205 Resolves: #2185741

[2.38.5-1]

  • Update to 2.38.5 Related: #2127468

[2.38.4-1]

  • Update to 2.38.4 Related: #2127468

[2.38.3-1]

  • Update to 2.38.3 Related: #2127468

[2.38.2-1]

  • Update to 2.38.2 Related: #2127468

[2.38.1-2]

  • Fix crashes on aarch64 Enable WPE renderer Related: #2127468

[2.38.1-1]

  • Update to 2.38.1 Related: #2127468

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

webkit2gtk3

2.38.5-1.el8_8.3

webkit2gtk3-devel

2.38.5-1.el8_8.3

webkit2gtk3-jsc

2.38.5-1.el8_8.3

webkit2gtk3-jsc-devel

2.38.5-1.el8_8.3

Oracle Linux x86_64

webkit2gtk3

2.38.5-1.el8_8.3

webkit2gtk3-devel

2.38.5-1.el8_8.3

webkit2gtk3-jsc

2.38.5-1.el8_8.3

webkit2gtk3-jsc-devel

2.38.5-1.el8_8.3

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
redhat
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
nvd
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web content files, causing a denial of service or arbitrary code execution. This CVE exists because of a CVE-2023-28205 security regression for the WebKitGTK package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

CVSS3: 8.8
debian
больше 2 лет назад

A flaw was found in the WebKitGTK package. An improper input validatio ...

rocky
около 2 лет назад

Important: webkit2gtk3 security update