Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4558-1

Опубликовано: 24 нояб. 2023
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 fixes the following issues:

Update to version 2.42.2 (bsc#1217210):

  • CVE-2023-41983: Processing web content may lead to a denial-of-service.
  • CVE-2023-42852: Processing web content may lead to arbitrary code execution.

Already previously fixed:

  • CVE-2022-32919: Visiting a website that frames malicious content may lead to UI spoofing (fixed already in 2.38.4).
  • CVE-2022-32933: A website may be able to track the websites a user visited in private browsing mode (fixed already in 2.38.0).
  • CVE-2022-46705: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
  • CVE-2022-46725: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
  • CVE-2023-32359: A user’s password may be read aloud by a text-to-speech accessibility feature (fixed already in 2.42.0).

Bug fixes:

  • Disable DMABuf renderer for NVIDIA proprietary drivers (bsc#1216778).

Список пакетов

SUSE Enterprise Storage 7.1
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
libwebkit2gtk-4_0-37-2.42.2-150200.91.1
libwebkit2gtk3-lang-2.42.2-150200.91.1
typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2-4_0-2.42.2-150200.91.1
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150200.91.1
webkit2gtk-4_0-injected-bundles-2.42.2-150200.91.1
webkit2gtk3-devel-2.42.2-150200.91.1

Описание

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2. A user's password may be read aloud by VoiceOver.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки

Описание

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Enterprise Storage 7.1:libjavascriptcoregtk-4_0-18-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk-4_0-37-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:libwebkit2gtk3-lang-2.42.2-150200.91.1
SUSE Enterprise Storage 7.1:typelib-1_0-JavaScriptCore-4_0-2.42.2-150200.91.1

Ссылки
Уязвимость SUSE-SU-2023:4558-1