ArchLinux: 201707-25: webkit2gtk: multiple issues
Summary
- CVE-2017-7018 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7030 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7034 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7037 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7039 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7046 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7048 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7055 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7056 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7061 (arbitrary code execution)
Several memory corruption issues have been found in WebKitGTK+ <2.16.5, leading to arbitrary code execution when processing maliciously
crafted web contents.
- CVE-2017-7064 (information disclosure)
An information disclosure issue has been found in WebKitGTK+ <= 2.16.5,
where an application may be able to read restricted memory.
Resolution
Upgrade to 2.16.6-1.
# pacman -Syu "webkit2gtk>=2.16.6-1"
The problems have been fixed upstream in version 2.16.6.
References
https://webkitgtk.org/security/WSA-2017-0006.html https://security.archlinux.org/CVE-2017-7018 https://security.archlinux.org/CVE-2017-7030 https://security.archlinux.org/CVE-2017-7034 https://security.archlinux.org/CVE-2017-7037 https://security.archlinux.org/CVE-2017-7039 https://security.archlinux.org/CVE-2017-7046 https://security.archlinux.org/CVE-2017-7048 https://security.archlinux.org/CVE-2017-7055 https://security.archlinux.org/CVE-2017-7056 https://security.archlinux.org/CVE-2017-7061 https://security.archlinux.org/CVE-2017-7064
Workaround
None.