MGASA-2023-0177 - Updated webkit2 packages fix security vulnerability

Publication date: 21 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0177.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-0108,
     CVE-2022-32885,
     CVE-2023-25358,
     CVE-2023-27932,
     CVE-2023-27954,
     CVE-2023-28205

HTML document may be able to render iframes with sensitive user
information (CVE-2022-0108)
maliciously crafted web content may lead to arbitrary code execution.
(CVE-2022-32885)
use-after-free vulnerability exists in WebCore::RenderLayer. This issue
allows remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web site.
(CVE-2023-25358)
maliciously crafted web content may bypass Same Origin Policy
(CVE-2023-27932)
Website may be able to track sensitive user information. Description: The
issue was addressed by removing origin information. (CVE-2023-27954)
maliciously crafted web content may lead to arbitrary code execution
(CVE-2023-28205)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31854
- https://webkitgtk.org/security/WSA-2023-0003.html
- https://webkitgtk.org/2023/04/20/webkitgtk2.38.6-released.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0108
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32885
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25358
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27932
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27954
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28205

SRPMS:
- 8/core/webkit2-2.38.6-1.mga8

Mageia 2023-0177: webkit2 security update

HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution

Summary

HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. (CVE-2023-25358) maliciously crafted web content may bypass Same Origin Policy (CVE-2023-27932) Website may be able to track sensitive user information. Description: The issue was addressed by removing origin information. (CVE-2023-27954) maliciously crafted web content may lead to arbitrary code execution (CVE-2023-28205)

References

- https://bugs.mageia.org/show_bug.cgi?id=31854

- https://webkitgtk.org/security/WSA-2023-0003.html

- https://webkitgtk.org/2023/04/20/webkitgtk2.38.6-released.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0108

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32885

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25358

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27932

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27954

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28205

Resolution

MGASA-2023-0177 - Updated webkit2 packages fix security vulnerability

SRPMS

- 8/core/webkit2-2.38.6-1.mga8

Severity
Publication date: 21 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0177.html
Type: security
CVE: CVE-2022-0108, CVE-2022-32885, CVE-2023-25358, CVE-2023-27932, CVE-2023-27954, CVE-2023-28205

Related News