Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4561-1

Опубликовано: 24 нояб. 2023
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 fixes the following issues:

Update to version 2.42.2 (bsc#1217210):

  • CVE-2023-41983: Processing web content may lead to a denial-of-service.
  • CVE-2023-42852: Processing web content may lead to arbitrary code execution.

Already previously fixed:

  • CVE-2022-32919: Visiting a website that frames malicious content may lead to UI spoofing (fixed already in 2.38.4).
  • CVE-2022-32933: A website may be able to track the websites a user visited in private browsing mode (fixed already in 2.38.0).
  • CVE-2022-46705: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
  • CVE-2022-46725: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).
  • CVE-2023-32359: A user’s password may be read aloud by a text-to-speech accessibility feature (fixed already in 2.42.0).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP4
WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150400.4.64.2
webkit2gtk-4_0-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-soup2-devel-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP5
WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150400.4.64.2
webkit2gtk-4_0-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-soup2-devel-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
WebKitGTK-4.1-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_1-2.42.2-150400.4.64.2
webkit2gtk-4_1-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-devel-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Desktop Applications 15 SP5
WebKitGTK-4.1-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_1-2.42.2-150400.4.64.2
webkit2gtk-4_1-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-devel-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Development Tools 15 SP4
WebKitGTK-6.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-6_0-1-2.42.2-150400.4.64.2
libwebkitgtk-6_0-4-2.42.2-150400.4.64.2
webkitgtk-6_0-injected-bundles-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Development Tools 15 SP5
WebKitGTK-6.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-6_0-1-2.42.2-150400.4.64.2
libwebkitgtk-6_0-4-2.42.2-150400.4.64.2
webkitgtk-6_0-injected-bundles-2.42.2-150400.4.64.2
openSUSE Leap 15.4
WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
WebKitGTK-4.1-lang-2.42.2-150400.4.64.2
WebKitGTK-6.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-32bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-64bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-32bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-64bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-6_0-1-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-32bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-64bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-32bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-64bit-2.42.2-150400.4.64.2
libwebkitgtk-6_0-4-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_1-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-6_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit-6_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKitWebProcessExtension-6_0-2.42.2-150400.4.64.2
webkit-jsc-4-2.42.2-150400.4.64.2
webkit-jsc-4.1-2.42.2-150400.4.64.2
webkit-jsc-6.0-2.42.2-150400.4.64.2
webkit2gtk-4_0-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk-4_1-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-devel-2.42.2-150400.4.64.2
webkit2gtk3-minibrowser-2.42.2-150400.4.64.2
webkit2gtk3-soup2-devel-2.42.2-150400.4.64.2
webkit2gtk3-soup2-minibrowser-2.42.2-150400.4.64.2
webkit2gtk4-devel-2.42.2-150400.4.64.2
webkit2gtk4-minibrowser-2.42.2-150400.4.64.2
webkitgtk-6_0-injected-bundles-2.42.2-150400.4.64.2
openSUSE Leap 15.5
WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
WebKitGTK-4.1-lang-2.42.2-150400.4.64.2
WebKitGTK-6.0-lang-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-32bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_0-18-64bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-32bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-4_1-0-64bit-2.42.2-150400.4.64.2
libjavascriptcoregtk-6_0-1-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-32bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_0-37-64bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-32bit-2.42.2-150400.4.64.2
libwebkit2gtk-4_1-0-64bit-2.42.2-150400.4.64.2
libwebkitgtk-6_0-4-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-4_1-2.42.2-150400.4.64.2
typelib-1_0-JavaScriptCore-6_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit-6_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_0-2.42.2-150400.4.64.2
typelib-1_0-WebKit2WebExtension-4_1-2.42.2-150400.4.64.2
typelib-1_0-WebKitWebProcessExtension-6_0-2.42.2-150400.4.64.2
webkit-jsc-4-2.42.2-150400.4.64.2
webkit-jsc-4.1-2.42.2-150400.4.64.2
webkit-jsc-6.0-2.42.2-150400.4.64.2
webkit2gtk-4_0-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk-4_1-injected-bundles-2.42.2-150400.4.64.2
webkit2gtk3-devel-2.42.2-150400.4.64.2
webkit2gtk3-minibrowser-2.42.2-150400.4.64.2
webkit2gtk3-soup2-devel-2.42.2-150400.4.64.2
webkit2gtk3-soup2-minibrowser-2.42.2-150400.4.64.2
webkit2gtk4-devel-2.42.2-150400.4.64.2
webkit2gtk4-minibrowser-2.42.2-150400.4.64.2
webkitgtk-6_0-injected-bundles-2.42.2-150400.4.64.2

Описание

The issue was addressed with improved UI handling. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. Visiting a website that frames malicious content may lead to UI spoofing.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Monterey 12.5. A website may be able to track the websites a user visited in Safari private browsing mode.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, Safari 16.2. Visiting a malicious website may lead to address bar spoofing.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.4 and iPadOS 16.4. Visiting a malicious website may lead to address bar spoofing.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2. A user's password may be read aloud by VoiceOver.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки

Описание

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:WebKitGTK-4.0-lang-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libjavascriptcoregtk-4_0-18-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libwebkit2gtk-4_0-37-2.42.2-150400.4.64.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:typelib-1_0-JavaScriptCore-4_0-2.42.2-150400.4.64.2

Ссылки
Уязвимость SUSE-SU-2023:4561-1