Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian DSA-5618-1: WebkitGTK Critical: Arbitrary Code Execution Risks

debian
Calendar Grey February 8, 2024
Debian Logo
Important safety patches released for webkit2gtk in Debian, rectifying numerous vulnerabilities that threaten user security. Immediate update recommended.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-23206

Summary

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-23206

An anonymous researcher discovered that a maliciously crafted
webpage may be able to fingerprint the user.

CVE-2024-23213

Wangtaiyu discovered that processing web content may lead to
arbitrary code execution.

CVE-2024-23222

Apple discovered that processing maliciously crafted web content
may lead to arbitrary code execution. Apple is aware of a report
that this issue may have been exploited.

For the oldstable distribution (bullseye), these problems have been fixed
in version 2.42.5-1~deb11u1.

For the stable distribution (bookworm), these problems have been fixed in
version 2.42.5-1~deb12u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updat...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
CVE ID: CVE-2024-23206 CVE-2024-23213 CVE-2024-23222

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here