Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE 42.3 Security Update: Important webkit2gtk3 Fixes

opensuse
Calendar Grey February 1, 2018
Dist Opensuse Esm H88
Addresses 89 security flaws in webkit2gtk3 for openSUSE, delivering essential updates and guidance for setup.
An update that fixes 89 vulnerabilities is now available.

Description

This update for webkit2gtk3 fixes the following issues:

Update to version 2.18.5:

+ Disable SharedArrayBuffers from Web API.

+ Reduce the precision of "high" resolution time to 1ms.

+ bsc#1075419 - Security fixes: includes improvements to mitigate the

effects of Spectre and Meltdown (CVE-2017-5753 and CVE-2017-5715).

Update to version 2.18.4:

+ Make WebDriver implementation more spec compliant.

+ Fix a bug when trying to remove cookies before a web process is

spawned.

+ WebKitWebDriver process no longer links to libjavascriptcoregtk.

+ Fix several memory leaks in GStreamer media backend.

+ bsc#1073654 - Security fixes: CVE-2017-13866, CVE-2017-13870,

CVE-2017-7156, CVE-2017-13856.

Update to version 2.18.3:

+ Improve calculation of font metrics to prevent scrollbars from being

shown unnecessarily in some cases.

+ Fix handling of null capabilities in WebDriver implementation.

+...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-118=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libjavascriptcoregtk-4_0-18-2.18.5-8.1

libjavascriptcoregtk-4_0-18-debuginfo-2.18.5-8.1

libwebkit2gtk-4_0-37-2.18.5-8.1

libwebkit2gtk-4_0-37-debuginfo-2.18.5-8.1

typelib-1_0-JavaScriptCore-4_0-2.18.5-8.1

typelib-1_0-WebKit2-4_0-2.18.5-8.1

typelib-1_0-WebKit2WebExtension-4_0-2.18.5-8.1

webkit-jsc-4-2.18.5-8.1

webkit-jsc-4-debuginfo-2.18.5-8.1

webkit2gtk-4_0-injected-bundles-2.18.5-8.1

webkit2gtk-4_0-injected-bundles-debuginfo-2.18.5-8.1

webkit2gtk3-debugsource-2.18.5-8.1

webkit2gtk3-devel-2.18.5-8.1

webkit2gtk3-plugin-process-gtk2-2.18.5-8.1

webkit2gtk3-plugin-process-gtk2-debuginfo-2.18.5-8.1

- openSUSE Leap 42.3 (x86_64):

libjavascriptcoregtk-4_0-18-32bit-2.18.5-8.1

libjavascriptcoregtk-4_0-18-debuginfo-32bit-2.18.5-8.1

libwebkit2gtk-4_0-37-32bit-2.18.5-8.1

libwebkit2gtk-4_0-37-debuginfo-32bit-2.18.5-8.1

- openSUSE Leap 42.3 (noarch):

libwebkit2gtk3-lang-2.18.5-8.1

References

https://www.suse.com/security/cve/CVE-2016-4692.html

https://www.suse.com/security/cve/CVE-2016-4743.html

https://www.suse.com/security/cve/CVE-2016-7586.html

https://www.suse.com/security/cve/CVE-2016-7587.html

https://www.suse.com/security/cve/CVE-2016-7589.html

https://www.suse.com/security/cve/CVE-2016-7592.html

https://www.suse.com/security/cve/CVE-2016-7598.html

https://www.suse.com/security/cve/CVE-2016-7599.html

https://www.suse.com/security/cve/CVE-2016-7610.html

https://www.suse.com/security/cve/CVE-2016-7623.html

https://www.suse.com/security/cve/CVE-2016-7632.html

https://www.suse.com/security/cve/CVE-2016-7635.html

https://www.suse.com/security/cve/CVE-2016-7639.html

https://www.suse.com/security/cve/CVE-2016-7641.html

https://www.suse.com/security/cve/CVE-2016-7645.html

https://www.suse.com/security/cve/CVE-2016-7652.html

https://www.suse.com/security/cve/CVE-2016-7654.html

https://www.suse.com/security/cve/CVE-2016-7656.html

https://www.suse.com/security/cve/CVE-2017-13788.html

https://www...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0326-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here