Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE Leap 15.2: 2021:0637-1 Important: WebKit2Gtk3 Issues

opensuse
Calendar Grey April 30, 2021
Dist Opensuse Esm H88
This release addresses significant vulnerabilities in webkit2gtk3, improving safety and performance for openSUSE users.
An update that fixes 10 vulnerabilities is now available

Description

This update for webkit2gtk3 fixes the following issues:

- Update to version 2.32.0 (bsc#1184155):

* Fix the authentication request port when URL omits the port.

* Fix iframe scrolling when main frame is scrolled in async

* scrolling mode.

* Stop using g_memdup.

* Show a warning message when overriding signal handler for

* threading suspension.

* Fix the build on RISC-V with GCC 11.

* Fix several crashes and rendering issues.

* Security fixes: CVE-2021-1788, CVE-2021-1844, CVE-2021-1871

- Update in version 2.30.6 (bsc#1184262):

* Update user agent quirks again for Google Docs and Google Drive.

* Fix several crashes and rendering issues.

* Security fixes: CVE-2020-27918, CVE-2020-29623, CVE-2021-1765

CVE-2021-1789, CVE-2021-1799, CVE-2021-1801, CVE-2021-1870.

- Update _constraints for armv6/armv7 (bsc#1182719)

- restore NPAPI plugin support which was removed in 2.32.0

This update was imported from...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-637=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

libjavascriptcoregtk-4_0-18-2.32.0-lp152.2.13.1

libjavascriptcoregtk-4_0-18-debuginfo-2.32.0-lp152.2.13.1

libwebkit2gtk-4_0-37-2.32.0-lp152.2.13.1

libwebkit2gtk-4_0-37-debuginfo-2.32.0-lp152.2.13.1

typelib-1_0-JavaScriptCore-4_0-2.32.0-lp152.2.13.1

typelib-1_0-WebKit2-4_0-2.32.0-lp152.2.13.1

typelib-1_0-WebKit2WebExtension-4_0-2.32.0-lp152.2.13.1

webkit-jsc-4-2.32.0-lp152.2.13.1

webkit-jsc-4-debuginfo-2.32.0-lp152.2.13.1

webkit2gtk-4_0-injected-bundles-2.32.0-lp152.2.13.1

webkit2gtk-4_0-injected-bundles-debuginfo-2.32.0-lp152.2.13.1

webkit2gtk3-debugsource-2.32.0-lp152.2.13.1

webkit2gtk3-devel-2.32.0-lp152.2.13.1

webkit2gtk3-minibrowser-2.32.0-lp152.2.13.1

webkit2gtk3-minibrowser-debuginfo-2.32.0-lp152.2.13.1

- openSUSE Leap 15.2 (x86_64):

libjavascriptcoregtk-4_0-18-32bit-2.32.0-lp152.2.13.1

libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.32.0-lp152.2.13.1

libwebkit2gtk-4_0-37-32bit-2.32.0-lp152.2.13.1

libwebkit2gtk-4_0-37-32bit-debuginfo-2.32.0-lp152.2.13.1

- openSUSE...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-27918.html

https://www.suse.com/security/cve/CVE-2020-29623.html

https://www.suse.com/security/cve/CVE-2021-1765.html

https://www.suse.com/security/cve/CVE-2021-1788.html

https://www.suse.com/security/cve/CVE-2021-1789.html

https://www.suse.com/security/cve/CVE-2021-1799.html

https://www.suse.com/security/cve/CVE-2021-1801.html

https://www.suse.com/security/cve/CVE-2021-1844.html

https://www.suse.com/security/cve/CVE-2021-1870.html

https://www.suse.com/security/cve/CVE-2021-1871.html

https://bugzilla.suse.com/1182719

https://bugzilla.suse.com/1184155

https://bugzilla.suse.com/1184262

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0637-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here