Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Fedora 30: 2019-d9a15be3ba Moderate: Webkit2gtk3 Security Update

fedora
Calendar Grey April 12, 2019
Scroller Fedora
Critical security patch released for Fedora 30 targeting various vulnerabilities in webkit2gtk3, featuring essential fixes and performance improvements.
* Do not allow changes in active URI before provisional load starts for non-API requests

Summary

WebKitGTK is the port of the portable web rendering engine WebKit to the

GTK platform.

This package contains WebKit2 based WebKitGTK for GTK 3.

* Do not allow changes in active URI before provisional load starts for non-API

requests. * Stop the threaded compositor when the page is not visible or layer

tree state is frozen. * Use WebKit HTTP source element again for adaptive

streaming fragments downloading. * Properly handle empty resources in

webkit_web_resource_get_data(). * Add quirk to ensure outlook.live.com uses the

modern UI. * Fix methods returing GObject or boxed types in JavaScriptCore GLib

API. * Ensure callback data is passed to functions and constructors with no

parameters in JavaScriptCore GLib API. * Fix rendering of complex text when the

font uses x,y origins. * Fix sound loop with Google Hangouts and WhatsApp

notifications. * Fix the build with GStreamer 1.12.5 and GST GL enabled. *

Detect SSE2 at compile time. * Fix several crashes and rendering issues. *

Security fixes: CVE-2019-6251, CVE-2019-11070.

[ 1 ] Bug #1667409 - CVE-2019-6251 epiphany: Improper input validation in embed/ephy-web-view.c

https://bugzilla.redhat.com/show_bug.cgi?id=1667409

su -c 'dnf upgrade --advisory FEDORA-2019-d9a15be3ba' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 30
Version: 2.24.1
Release: 1.fc30
Summary: GTK Web content engine library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.