Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DSA-5308-1 Moderate: WebkitGTK Memory Disclosure and Code Execution

debian
Calendar Grey December 31, 2022
Debian Logo
A crucial update has been advised for webkit2gtk to address significant vulnerabilities that could lead to risks such as memory leakage and arbitrary code execution.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42852

Summary

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2022-42852

hazbinhotel discovered that processing maliciously crafted web
content may result in the disclosure of process memory.

CVE-2022-42856

Clement Lecigne discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-42867

Maddie Stone discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-46692

KirtiKumar Anandrao Ramchandani discovered that processing
maliciously crafted web content may bypass Same Origin Policy.

CVE-2022-46698

Dohyun Lee and Ryan Shin discovered that processing maliciously
crafted web content may disclose sensitive user information.

CVE-2022-46699

Samuel Gross discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-46700

Samuel Gross discovered that processing maliciously crafted web
content may lea...

Read the Full Advisory

Package: webkit2gtk
CVE ID: CVE-2022-42852 CVE-2022-42856 CVE-2022-42867 CVE-2022-46692

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here