Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian 11 DSA-5396-1 High Severity WebKitGTK Code Execution Flaws

debian
Calendar Grey May 3, 2023
Debian Logo
Recent Debian updates address key vulnerabilities in the webkit2gtk framework, aiming to prevent unauthorized code execution and safeguard confidential information from tracking
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-0108

Summary

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2022-0108

Luan Herrera discovered that an HTML document may be able to
render iframes with sensitive user information.

CVE-2022-32885

P1umer and Q1IQ discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2023-27932

An anonymous researcher discovered that processing maliciously
crafted web content may bypass Same Origin Policy.

CVE-2023-27954

An anonymous researcher discovered that a website may be able to
track sensitive user information.

CVE-2023-28205

Clement Lecigne and Donncha O Cearbhaill discovered that
processing maliciously crafted web content may lead to arbitrary
code execution. Apple is aware of a report that this issue may
have been actively exploited.

For the stable distribution (bullseye), these problems have been fixed in
version 2.40.1-1~deb11u1.

We recommend that you upgrade your webkit2gtk packages.

For the det...

Read the Full Advisory

Package: webkit2gtk
CVE ID: CVE-2022-0108 CVE-2022-32885 CVE-2023-27932 CVE-2023-27954

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here