Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 34: FEDORA-2021-cf7d8c7b1a Critical: Webkit2gtk3 Code Execution

fedora
Calendar Grey July 28, 2021
Dist Fedora Esm H88
The latest Fedora 34 update tackles security vulnerabilities in webkit2gtk3, resolves crashing issues, and improves features for better accessibility.
* Properly set the cookies settings after a network process crash

Summary

WebKitGTK is the port of the portable web rendering engine WebKit to the

GTK platform.

This package contains WebKit2 based WebKitGTK for GTK 3.

* Properly set the cookies settings after a network process crash. * Fix

accessibility tree after a cross site navigation with PSON enabled. * Ensure

WebKitScriptWorld::window-object-cleared signal is always emitted. * Fix

several crashes and rendering issues. * Security fixes: CVE-2021-21775,

CVE-2021-21779, CVE-2021-30663, CVE-2021-30665, CVE-2021-30689, CVE-2021-30720,

CVE-2021-30734, CVE-2021-30744, CVE-2021-30749, CVE-2021-30795, CVE-2021-30797,

CVE-2021-30799

* Fri Jul 23 2021 Michael Catanzaro - 2.32.3-1

- Update to 2.32.3

[ 1 ] Bug #1986864 - CVE-2021-21775 webkit2gtk3: webkitgtk: A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of WebKit. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986864

[ 2 ] Bug #1986867 - CVE-2021-21779 webkit2gtk3: webkitgtk: A use-after-free vulnerability exists in the way that WebKit GraphicsContext handles certain events. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986867

[ 3 ] Bug #1986873 - CVE-2021-30663 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986873

[ 4 ] Bug #1986876 - CVE-2021-30665 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986876

[ 5 ] Bug #1986882 - CVE-2021-30689 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to universal cross site scripting. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986882

[ 6 ] Bug #1986884 - CVE-2021-30720 webkit2gtk3: webkitgtk: A malicious website may be able to access restricted ports on arbitrary servers. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986884

[ 7 ] Bug #1986887 - CVE-2021-30734 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986887

[ 8 ] Bug #1986889 - CVE-2021-30744 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to universal cross site scripting. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986889

[ 9 ] Bug #1986891 - CVE-2021-30749 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986891

[ 10 ] Bug #1986901 - CVE-2021-30795 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986901

[ 11 ] Bug #1986904 - CVE-2021-30797 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986904

[ 12 ] Bug #1986908 - CVE-2021-30799 webkit2gtk3: webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution. [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1986908

su -c 'dnf upgrade --advisory FEDORA-2021-cf7d8c7b1a' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 34
Version: 2.32.3
Release: 1.fc34
Summary: GTK Web content engine library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here