Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian DSA-5527-1: Critical WebKit2GTK Memory Corruption Issues

debian
Calendar Grey October 12, 2023
Debian Logo
Update webkit2gtk components immediately because of severe vulnerabilities in Debian, leading to potential memory leaks and unauthorized code execution risks.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2023-39928

Summary

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2023-39928

Marcin Noga discovered that a specially crafted web page can abuse
a vulnerability in the MediaRecorder API to cause memory
corruption and potentially arbitrary code execution.

CVE-2023-41074

Junsung Lee and Me Li discovered that processing web content may
lead to arbitrary code execution.

CVE-2023-41993

Bill Marczak and Maddie Stone discovered that processing web
content may lead to arbitrary code execution. Apple is aware of a
report that this issue may have been actively exploited.

For the oldstable distribution (bullseye), these problems have been fixed
in version 2.42.1-1~deb11u1.

For the stable distribution (bookworm), these problems have been fixed in
version 2.42.1-1~deb12u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/sour...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
CVE ID: CVE-2023-39928 CVE-2023-41074 CVE-2023-41993

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here