Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian Bullseye DSA-5084-1 Critical: WPE WebKit Code Execution

debian
Calendar Grey February 19, 2022
Debian Logo
Uncover essential security patches for WPE WebKit within Debian stable, targeting various vulnerabilities.
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-22589

Summary

The following vulnerabilities have been discovered in the WPE WebKit
web engine:

CVE-2022-22589

Heige and Bo Qu discovered that processing a maliciously crafted
mail message may lead to running arbitrary javascript.

CVE-2022-22590

Toan Pham discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-22592

Prakash discovered that processing maliciously crafted web content
may prevent Content Security Policy from being enforced.

CVE-2022-22620

An anonymous researcher discovered that processing maliciously
crafted web content may lead to arbitrary code execution. Apple is
aware of a report that this issue may have been actively
exploited.

For the stable distribution (bullseye), these problems have been fixed in
version 2.34.6-1~deb11u1.

We recommend that you upgrade your wpewebkit packages.

For the detailed security status of wpewebkit please refer to
its security tracker page at:
https://security-tracker.debian.org/track...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: wpewebkit
CVE ID: CVE-2022-22589 CVE-2022-22590 CVE-2022-22592 CVE-2022-22620

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here