Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Debian LTS DLA-4051-1: Critical webkit2gtk Updates for Multiple Threats

debian lts
Calendar Grey February 13, 2025
Dist Debian Esm H88
Debian LTS Advisory DLA-4052-1 has been issued regarding vulnerabilities in openssl to enhance user safety.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2025-24143

Summary

CVE-2025-24143

An anonymous researcher discovered that a maliciously crafted
webpage may be able to fingerprint the user.

CVE-2025-24150

Johan Carlsson discovered that copying a URL from Web Inspector
may lead to command injection.

CVE-2025-24158

Q1IQ and P1umer discovered that processing web content may lead to
a denial-of-service.

CVE-2025-24162

linjy and chluo discovered that processing maliciously crafted web
content may lead to an unexpected process crash.

For Debian 11 bullseye, these problems have been fixed in version
2.46.6-1~deb11u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/webkit2gtk

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
Version: 2.46.6-1~deb11u1
CVE ID: CVE-2025-24143 CVE-2025-24150 CVE-2025-24158 CVE-2025-24162

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here