Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Debian: DLA-3274-1 Critical: WebKitGTK Code Execution Risk

debian lts
Calendar Grey January 19, 2023
Dist Debian Esm H88
Update issued for various security flaws in webkit2gtk on Debian LTS. Ensure upgrades to safeguard information and enhance system integrity.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42852

Summary

CVE-2022-42852

hazbinhotel discovered that processing maliciously crafted web
content may result in the disclosure of process memory.

CVE-2022-42856

Clement Lecigne discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-42867

Maddie Stone discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-46692

KirtiKumar Anandrao Ramchandani discovered that processing
maliciously crafted web content may bypass Same Origin Policy.

CVE-2022-46698

Dohyun Lee and Ryan Shin discovered that processing maliciously
crafted web content may disclose sensitive user information.

CVE-2022-46699

Samuel Gross discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2022-46700

Samuel Gross discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
Version: 2.38.3-1~deb10u1
CVE ID: CVE-2022-42852 CVE-2022-42856 CVE-2022-42867 CVE-2022-46692

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here