Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 10: DLA-3419-1 Critical: WebKitGTK Code Execution Threats

debian lts
Calendar Grey May 12, 2023
Dist Debian Esm H88
Keeping WebKitGTK updated is crucial to guard against potential code execution risks and safeguard user privacy issues in Debian.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-0108

Summary

CVE-2022-0108

Luan Herrera discovered that an HTML document may be able to
render iframes with sensitive user information.

CVE-2022-32885

P1umer and Q1IQ discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2023-27932

An anonymous researcher discovered that processing maliciously
crafted web content may bypass Same Origin Policy.

CVE-2023-27954

An anonymous researcher discovered that a website may be able to
track sensitive user information.

CVE-2023-28205

Clement Lecigne and Donncha O Cearbhaill discovered that
processing maliciously crafted web content may lead to arbitrary
code execution. Apple is aware of a report that this issue may
have been actively exploited.

For Debian 10 buster, these problems have been fixed in version
2.38.6-0+deb10u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
Version: 2.38.6-0+deb10u1
CVE ID: CVE-2022-0108 CVE-2022-32885 CVE-2023-27932 CVE-2023-27954

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here