Описание
Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues:
Update to version 2.42.2 (bsc#1217210):
- CVE-2023-41983: Processing web content may lead to a denial-of-service.
- CVE-2023-42852: Processing web content may lead to arbitrary code execution.
Already previously fixed:
- CVE-2022-32919: Visiting a website that frames malicious content may lead to UI spoofing (fixed already in 2.38.4).
- CVE-2022-32933: A website may be able to track the websites a user visited in private browsing mode (fixed already in 2.38.0).
- CVE-2022-46705: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
- CVE-2022-46725: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
- CVE-2023-32359: A user’s password may be read aloud by a text-to-speech accessibility feature (fixed already in 2.42.0).
Bug fixes:
- Disable DMABuf renderer for NVIDIA proprietary drivers (bsc#1216778).
Список пакетов
SUSE Enterprise Storage 7.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
SUSE Linux Enterprise Server 15 SP2-LTSS
SUSE Linux Enterprise Server 15 SP3-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP3
Ссылки
- Link for SUSE-SU-2023:4558-1
- E-Mail link for SUSE-SU-2023:4558-1
- SUSE Security Ratings
- SUSE Bug 1216778
- SUSE Bug 1217210
- SUSE CVE CVE-2022-32919 page
- SUSE CVE CVE-2022-32933 page
- SUSE CVE CVE-2022-46705 page
- SUSE CVE CVE-2022-46725 page
- SUSE CVE CVE-2023-32359 page
- SUSE CVE CVE-2023-41983 page
- SUSE CVE CVE-2023-42852 page
Описание
The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.
Затронутые продукты
Ссылки
- CVE-2022-32919
- SUSE Bug 1217210
Описание
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.
Затронутые продукты
Ссылки
- CVE-2022-32933
- SUSE Bug 1217210
Описание
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.
Затронутые продукты
Ссылки
- CVE-2022-46705
- SUSE Bug 1217210
Описание
A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.
Затронутые продукты
Ссылки
- CVE-2022-46725
- SUSE Bug 1217210
Описание
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2. A user's password may be read aloud by VoiceOver.
Затронутые продукты
Ссылки
- CVE-2023-32359
- SUSE Bug 1217210
- SUSE Bug 1217568
Описание
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
Затронутые продукты
Ссылки
- CVE-2023-41983
- SUSE Bug 1217210
Описание
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
Затронутые продукты
Ссылки
- CVE-2023-42852
- SUSE Bug 1217210
- SUSE Bug 1217568