Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Mageia 8 MGASA-2023-0197 High Severity Webkit2 Security Advisory

mageia
Calendar Grey June 15, 2023
Scroller Mageia
Revised webkit2 software for Mageia tackles severe vulnerabilities, such as memory corruption and improper object lifecycle handling.
Out-of-bounds read (CVE-2023-28204) Use-after-free issue (CVE-2023-32373) References: - https://bugs.mageia.org/show_bug.cgi?id=31986

Summary

Out-of-bounds read (CVE-2023-28204) Use-after-free issue (CVE-2023-32373)

References

- https://bugs.mageia.org/show_bug.cgi?id=31986

- https://support.apple.com/en-us/102735

- https://webkitgtk.org/security/WSA-2023-0004.html

- https://webkitgtk.org/2023/05/29/webkitgtk2.40.2-released.html

- https://www.cve.org/CVERecord?id=CVE-2023-28204

- https://www.cve.org/CVERecord?id=CVE-2023-32373

Resolution

SRPMS

- 8/core/unifdef-2.12-1.mga8

- 8/core/libwpe-1.14.1-1.mga8

- 8/core/wpebackend-fdo-1.14.2-1.mga8

- 8/core/libavif-0.11.1-1.mga8

- 8/core/webkit2-2.40.2-1.mga8

Publication date: 15 Jun 2023
URL: https://advisories.mageia.org/MGASA-2023-0197.html
Type: security
CVE: CVE-2023-28204, CVE-2023-32373

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.