Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1206-1

Опубликовано: 15 апр. 2019
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 to version 2.24.0 fixes the following issue:

Security issue fixed:

  • CVE-2019-8375: Fixed an issue in UIProcess subsystem which could allow the script dialog size to exceed the web view size leading to Buffer Overflow or other unspecified impact (bsc#1126768).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libjavascriptcoregtk-4_0-18-2.24.0-lp150.2.16.1
libjavascriptcoregtk-4_0-18-32bit-2.24.0-lp150.2.16.1
libwebkit2gtk-4_0-37-2.24.0-lp150.2.16.1
libwebkit2gtk-4_0-37-32bit-2.24.0-lp150.2.16.1
libwebkit2gtk3-lang-2.24.0-lp150.2.16.1
typelib-1_0-JavaScriptCore-4_0-2.24.0-lp150.2.16.1
typelib-1_0-WebKit2-4_0-2.24.0-lp150.2.16.1
typelib-1_0-WebKit2WebExtension-4_0-2.24.0-lp150.2.16.1
webkit-jsc-4-2.24.0-lp150.2.16.1
webkit2gtk-4_0-injected-bundles-2.24.0-lp150.2.16.1
webkit2gtk3-devel-2.24.0-lp150.2.16.1
webkit2gtk3-minibrowser-2.24.0-lp150.2.16.1
webkit2gtk3-plugin-process-gtk2-2.24.0-lp150.2.16.1

Описание

The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).


Затронутые продукты
openSUSE Leap 15.0:libjavascriptcoregtk-4_0-18-2.24.0-lp150.2.16.1
openSUSE Leap 15.0:libjavascriptcoregtk-4_0-18-32bit-2.24.0-lp150.2.16.1
openSUSE Leap 15.0:libwebkit2gtk-4_0-37-2.24.0-lp150.2.16.1
openSUSE Leap 15.0:libwebkit2gtk-4_0-37-32bit-2.24.0-lp150.2.16.1

Ссылки