Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0278-1

Опубликовано: 01 мар. 2020
Источник: suse-cvrf

Описание

Security update for webkit2gtk3

This update for webkit2gtk3 to version 2.26.4 fixes the following issues:

Security issues fixed:

  • CVE-2019-8835: Fixed multiple memory corruption issues (bsc#1161719).
  • CVE-2019-8844: Fixed multiple memory corruption issues (bsc#1161719).
  • CVE-2019-8846: Fixed a use-after-free issue (bsc#1161719).
  • CVE-2020-3862: Fixed a memory handling issue (bsc#1163809).
  • CVE-2020-3864: Fixed a logic issue in the DOM object context handling (bsc#1163809).
  • CVE-2020-3865: Fixed a logic issue in the DOM object context handling (bsc#1163809).
  • CVE-2020-3867: Fixed an XSS issue (bsc#1163809).
  • CVE-2020-3868: Fixed multiple memory corruption issues that could have lead to arbitrary code execution (bsc#1163809).

Non-security issues fixed:

  • Fixed issues while trying to play a video on NextCloud.
  • Fixed vertical alignment of text containing arabic diacritics.
  • Fixed build with icu 65.1.
  • Fixed page loading errors with websites using HSTS.
  • Fixed web process crash when displaying a KaTeX formula.
  • Fixed several crashes and rendering issues.
  • Switched to a single web process for Evolution and geary (bsc#1159329 glgo#GNOME/evolution#587).

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.1
libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1
libwebkit2gtk3-lang-2.26.4-lp151.2.12.1
typelib-1_0-JavaScriptCore-4_0-2.26.4-lp151.2.12.1
typelib-1_0-WebKit2-4_0-2.26.4-lp151.2.12.1
typelib-1_0-WebKit2WebExtension-4_0-2.26.4-lp151.2.12.1
webkit-jsc-4-2.26.4-lp151.2.12.1
webkit2gtk-4_0-injected-bundles-2.26.4-lp151.2.12.1
webkit2gtk3-devel-2.26.4-lp151.2.12.1
webkit2gtk3-minibrowser-2.26.4-lp151.2.12.1

Описание

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

A denial of service issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. A malicious website may be able to cause a denial of service.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to universal cross site scripting.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки

Описание

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.


Затронутые продукты
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libjavascriptcoregtk-4_0-18-32bit-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-2.26.4-lp151.2.12.1
openSUSE Leap 15.1:libwebkit2gtk-4_0-37-32bit-2.26.4-lp151.2.12.1

Ссылки
Уязвимость openSUSE-SU-2020:0278-1