This update for webkit2gtk3 fixes the following issues:
- Update to version 2.34.3 (bsc#1194019).
- CVE-2021-30887: Fixed logic issue allowing unexpectedly unenforced
Content Security Policy when processing maliciously crafted web content.
- CVE-2021-30890: Fixed logic issue allowing universal cross site
scripting when processing maliciously crafted web content.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2022-182=1
- openSUSE Leap 15.4 (noarch):
libwebkit2gtk3-lang-2.34.3-23.3
https://www.suse.com/security/cve/CVE-2019-8766.html
https://www.suse.com/security/cve/CVE-2019-8782.html
https://www.suse.com/security/cve/CVE-2019-8808.html
https://www.suse.com/security/cve/CVE-2019-8815.html
https://www.suse.com/security/cve/CVE-2020-13753.html
https://www.suse.com/security/cve/CVE-2020-27918.html
https://www.suse.com/security/cve/CVE-2020-29623.html
https://www.suse.com/security/cve/CVE-2020-3902.html
https://www.suse.com/security/cve/CVE-2020-9802.html
https://www.suse.com/security/cve/CVE-2020-9803.html
https://www.suse.com/security/cve/CVE-2020-9805.html
https://www.suse.com/security/cve/CVE-2020-9947.html
https://www.suse.com/security/cve/CVE-2020-9948.html
https://www.suse.com/security/cve/CVE-2020-9951.html
https://www.suse.com/security/cve/CVE-2020-9952.html
https://www.suse.com/security/cve/CVE-2021-1765.html
https://www.suse.com/security/cve/CVE-2021-1788.html
https://www.suse.com/security/cve/CVE-2021-1817.html
https://www.suse.com/security/cve/CVE-2021-1820.html
https://w...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.