Alerts This Week
Warning Icon 1 469
Alerts This Week
Warning Icon 1 469

Debian: DSA-5899-1 moderate: webkit2gtk denial of service and xss

debian
Calendar Grey April 10, 2025
Debian Logo
Enhance the webkit2gtk package in Debian to resolve severe security vulnerabilities and mitigate risks of attacks stemming from harmful content.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54551

Summary

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-54551

ajajfxhj discovered that processing web content may lead to a
denial-of-service.

CVE-2025-24208

Muhammad Zaid Ghifari and Kalimantan Utara discovered that loading
a malicious iframe may lead to a cross-site scripting attack.

CVE-2025-24209

Francisco Alonso and an anonymous researcher discovered that
processing maliciously crafted web content may lead to an
unexpected process crash.

CVE-2025-24213

The Google V8 Security Team discovered that a type confusion issue
could lead to memory corruption. Note that this CVE is fixed only
on ARM architectures. x86_64 is not vulnerable, x86 is not
vulnerable when the SSE2 instruction set is enabled; but other
architectures remain vulnerable.

CVE-2025-24216

Paul Bakker discovered that processing maliciously crafted web
content may lead to an unexpected Safari crash.

CVE-2025-24264

Gary Kwong and an anonymous resear...

Read the Full Advisory

Package: webkit2gtk
CVE ID: CVE-2024-54551 CVE-2025-24208 CVE-2025-24209 CVE-2025-24213

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here