Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

SUSE: 2018:0219-1 Important: Webkit2gtk3 Security Fixes Overview

suse
Calendar Grey January 25, 2018
Scroller Suse
A significant release for webkit2gtk3 has been issued, resolving 89 concerns, which feature urgent security flaws.
An update that fixes 89 vulnerabilities is now available.

Summary

This update for webkit2gtk3 fixes the following issues: Update to version 2.18.5: + Disable SharedArrayBuffers from Web API. + Reduce the precision of "high" resolution time to 1ms. + bsc#1075419 - Security fixes: includes improvements to mitigate the effects of Spectre and Meltdown (CVE-2017-5753 and CVE-2017-5715). Update to version 2.18.4: + Make WebDriver implementation more spec compliant. + Fix a bug when trying to remove cookies before a web process is spawned. + WebKitWebDriver process no longer links to libjavascriptcoregtk. + Fix several memory leaks in GStreamer media backend. + bsc#1073654 - Security fixes: CVE-2017-13866, CVE-2017-13870, CVE-2017-7156, CVE-2017-13856. Update to version 2.18.3: + Improve calculation of font metrics to prevent scrollbars from being

References

#1020950 #1024749 #1050469 #1066892 #1069925

#1073654 #1075419

Cross- CVE-2016-4692 CVE-2016-4743 CVE-2016-7586

CVE-2016-7587 CVE-2016-7589 CVE-2016-7592

CVE-2016-7598 CVE-2016-7599 CVE-2016-7610

CVE-2016-7623 CVE-2016-7632 CVE-2016-7635

CVE-2016-7639 CVE-2016-7641 CVE-2016-7645

CVE-2016-7652 CVE-2016-7654 CVE-2016-7656

CVE-2017-13788 CVE-2017-13798 CVE-2017-13803

CVE-2017-13856 CVE-2017-13866 CVE-2017-13870

CVE-2017-2350 CVE-2017-2354 CVE-2017-2355

CVE-2017-2356 CVE-2017-2362 CVE-2017-2363

CVE-2017-2364 CVE-2017-2365 CVE-2017-2366

CVE-2017-2369 CVE-2017-2371 CVE-2017-2373

CVE-2017-2496 CVE-2017-2510 CVE-2017-2539

CVE-2017-5715 CVE-2017-5753 CVE-2017-5754

CVE-2017-7006 CVE-2017-7011 CVE-2017...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0219-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.