Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:0639-1

Опубликовано: 21 фев. 2025
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 fixes the following issues:

Update to version 2.46.6 (bsc#1236946):

  • CVE-2025-24143: A maliciously crafted webpage may be able to fingerprint the user.
  • CVE-2025-24150: Copying a URL from Web Inspector may lead to command injection.
  • CVE-2025-24158: Processing web content may lead to a denial-of-service.
  • CVE-2025-24162: Processing maliciously crafted web content may lead to an unexpected process crash.

Already fixed in previous releases:

  • CVE-2024-54543: Processing maliciously crafted web content may lead to memory corruption.
  • CVE-2024-27856: Processing a file may lead to unexpected app termination or arbitrary code execution.
  • CVE-2024-54658: Processing web content may lead to a denial-of-service.

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
libwebkit2gtk-4_0-37-2.46.6-4.28.1
libwebkit2gtk3-lang-2.46.6-4.28.1
typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1
typelib-1_0-WebKit2-4_0-2.46.6-4.28.1
typelib-1_0-WebKit2WebExtension-4_0-2.46.6-4.28.1
webkit2gtk-4_0-injected-bundles-2.46.6-4.28.1
webkit2gtk3-devel-2.46.6-4.28.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
libwebkit2gtk-4_0-37-2.46.6-4.28.1
libwebkit2gtk3-lang-2.46.6-4.28.1
typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1
typelib-1_0-WebKit2-4_0-2.46.6-4.28.1
typelib-1_0-WebKit2WebExtension-4_0-2.46.6-4.28.1
webkit2gtk-4_0-injected-bundles-2.46.6-4.28.1
webkit2gtk3-devel-2.46.6-4.28.1

Описание

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, iOS 16.7.8 and iPadOS 16.7.8, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, tvOS 17.5, visionOS 1.2. Processing a file may lead to unexpected app termination or arbitrary code execution.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.2, tvOS 18.2, Safari 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to memory corruption.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, Safari 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки

Описание

This issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:libjavascriptcoregtk-4_0-18-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk-4_0-37-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libwebkit2gtk3-lang-2.46.6-4.28.1
SUSE Linux Enterprise Server 12 SP5-LTSS:typelib-1_0-JavaScriptCore-4_0-2.46.6-4.28.1

Ссылки
Уязвимость SUSE-SU-2025:0639-1