Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4207-1

Опубликовано: 23 нояб. 2022
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

Security fixes:

  • CVE-2022-32888: Fixed possible arbitrary code execution via maliciously crafted web content (bsc#1205121).
  • CVE-2022-32923: Fixed possible information leak via maliciously crafted web content (bsc#1205122).
  • CVE-2022-42799: Fixed user interface spoofing when visiting a malicious website (bsc#1205123).
  • CVE-2022-42823: Fixed possible arbitrary code execution via maliciously crafted web content (bsc#1205120).
  • CVE-2022-42824: Fixed possible sensitive user information leak via maliciously crafted web content (bsc#1205124).

Update to version 2.38.2:

  • Fix scrolling issues in some sites having fixed background.
  • Fix prolonged buffering during progressive live playback.
  • Fix the build with accessibility disabled.
  • Fix several crashes and rendering issues.

Update to version 2.38.1:

  • Make xdg-dbus-proxy work if host session bus address is an abstract socket.
  • Use a single xdg-dbus-proxy process when sandbox is enabled.
  • Fix high resolution video playback due to unimplemented changeType operation.
  • Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.
  • Fix player stucking in buffering (paused) state for progressive streaming.
  • Do not try to preconnect on link click when link preconnect setting is disabled.
  • Fix close status code returned when the client closes a WebSocket in some cases.
  • Fix media player duration calculation.
  • Fix several crashes and rendering issues.

Update to version 2.38.0:

  • New media controls UI style.
  • Add new API to set WebView's Content-Security-Policy for web extensions support.
  • Make it possible to use the remote inspector from other browsers using WEBKIT_INSPECTOR_HTTP_SERVER env var.
  • MediaSession is enabled by default, allowing remote media control using MPRIS.
  • Add support for PDF documents using PDF.js.

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP4
libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150400.4.22.1
webkit2gtk-4_0-injected-bundles-2.38.2-150400.4.22.1
webkit2gtk3-soup2-devel-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
libjavascriptcoregtk-4_1-0-2.38.2-150400.4.22.1
libwebkit2gtk-4_1-0-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-4_1-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-4_1-2.38.2-150400.4.22.1
typelib-1_0-WebKit2WebExtension-4_1-2.38.2-150400.4.22.1
webkit2gtk-4_1-injected-bundles-2.38.2-150400.4.22.1
webkit2gtk3-devel-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Development Tools 15 SP4
libjavascriptcoregtk-5_0-0-2.38.2-150400.4.22.1
libwebkit2gtk-5_0-0-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-5_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-5_0-2.38.2-150400.4.22.1
webkit2gtk-5_0-injected-bundles-2.38.2-150400.4.22.1
openSUSE Leap 15.4
WebKit2GTK-4.0-lang-2.38.2-150400.4.22.1
WebKit2GTK-4.1-lang-2.38.2-150400.4.22.1
WebKit2GTK-5.0-lang-2.38.2-150400.4.22.1
libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
libjavascriptcoregtk-4_0-18-32bit-2.38.2-150400.4.22.1
libjavascriptcoregtk-4_1-0-2.38.2-150400.4.22.1
libjavascriptcoregtk-4_1-0-32bit-2.38.2-150400.4.22.1
libjavascriptcoregtk-5_0-0-2.38.2-150400.4.22.1
libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
libwebkit2gtk-4_0-37-32bit-2.38.2-150400.4.22.1
libwebkit2gtk-4_1-0-2.38.2-150400.4.22.1
libwebkit2gtk-4_1-0-32bit-2.38.2-150400.4.22.1
libwebkit2gtk-5_0-0-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-4_1-2.38.2-150400.4.22.1
typelib-1_0-JavaScriptCore-5_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-4_1-2.38.2-150400.4.22.1
typelib-1_0-WebKit2-5_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150400.4.22.1
typelib-1_0-WebKit2WebExtension-4_1-2.38.2-150400.4.22.1
typelib-1_0-WebKit2WebExtension-5_0-2.38.2-150400.4.22.1
webkit-jsc-4-2.38.2-150400.4.22.1
webkit-jsc-4.1-2.38.2-150400.4.22.1
webkit-jsc-5.0-2.38.2-150400.4.22.1
webkit2gtk-4_0-injected-bundles-2.38.2-150400.4.22.1
webkit2gtk-4_1-injected-bundles-2.38.2-150400.4.22.1
webkit2gtk-5_0-injected-bundles-2.38.2-150400.4.22.1
webkit2gtk3-devel-2.38.2-150400.4.22.1
webkit2gtk3-minibrowser-2.38.2-150400.4.22.1
webkit2gtk3-soup2-devel-2.38.2-150400.4.22.1
webkit2gtk3-soup2-minibrowser-2.38.2-150400.4.22.1
webkit2gtk4-devel-2.38.2-150400.4.22.1
webkit2gtk4-minibrowser-2.38.2-150400.4.22.1

Описание

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, iOS 15.7 and iPadOS 15.7, watchOS 9, macOS Monterey 12.6, tvOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1

Ссылки

Описание

A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1

Ссылки

Описание

The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1

Ссылки

Описание

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1

Ссылки

Описание

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.38.2-150400.4.22.1
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-WebKit2-4_0-2.38.2-150400.4.22.1

Ссылки