Описание
Security update for webkitgtk
This update fixes the following security issues:
- Fix SSL connection issues with some websites after the POODLE vulnerability fix.
- Fix a crash when loading flash plugins.
- Fix build on GNU Hurd - Fix build on OS X.
- Fix documentation of webkit_print_operation_get_page_setup().
- Security fixes: CVE-2014-1344, CVE-2014-1384, CVE-2014-1385, CVE-2014-1386, CVE-2014-1387, CVE-2014-1388, CVE-2014-1389, CVE-2014-1390, CVE-2015-2330. (bnc#879607, bnc#871792)
- Pass autoreconf and enable libtool BuildRequires: Needed for above patch since it touches the buildsystem.
- Bugs fixed: boo#871792, boo#879607 and boo#879607.
Список пакетов
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
Ссылки
- Link for SUSE-SU-2015:0688-1
- E-Mail link for SUSE-SU-2015:0688-1
- SUSE Security Ratings
- SUSE Bug 866728
- SUSE Bug 871792
- SUSE Bug 879607
- SUSE Bug 883026
- SUSE CVE CVE-2014-1344 page
- SUSE CVE CVE-2014-1384 page
- SUSE CVE CVE-2014-1385 page
- SUSE CVE CVE-2014-1386 page
- SUSE CVE CVE-2014-1387 page
- SUSE CVE CVE-2014-1388 page
- SUSE CVE CVE-2014-1389 page
- SUSE CVE CVE-2014-1390 page
- SUSE CVE CVE-2015-2330 page
Описание
WebKit, as used in Apple Safari before 6.1.4 and 7.x before 7.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-05-21-1.
Затронутые продукты
Ссылки
- CVE-2014-1344
- SUSE Bug 879607
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1384
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1385
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1386
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1387
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1388
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1389
- SUSE Bug 892084
Описание
WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.
Затронутые продукты
Ссылки
- CVE-2014-1390
- SUSE Bug 892084
Описание
Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies.
Затронутые продукты
Ссылки
- CVE-2015-2330
- SUSE Bug 922895