Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-4558-1 Moderate: Webkit2Gtk Cross-Site Scripting Flaws

debian
Calendar Grey November 4, 2019
Debian Logo
A set of five security flaws was discovered in the webkit2gtk browser engine, featuring issues such as cross-origin resource sharing vulnerabilities and potential remote code execution.
Several vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2019-8625

Summary

Several vulnerabilities have been discovered in the webkit2gtk web engine:

CVE-2019-8625

Sergei Glazunov discovered that maliciously crafted web content
may lead to universal cross site scripting.

CVE-2019-8720

Wen Xu discovered that maliciously crafted web content may lead to
arbitrary code execution.

CVE-2019-8769

Pierre Reimertz discovered that visiting a maliciously crafted
website may reveal browsing history.

CVE-2019-8771

Eliya Stein discovered that maliciously crafted web content may
violate iframe sandboxing policy.

For the stable distribution (buster), these problems have been fixed in
version 2.26.1-3~deb10u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
CVE ID: CVE-2019-8625 CVE-2019-8720 CVE-2019-8769 CVE-2019-8771

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here