Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2021:3164-2 Important: Webkitgtk2 Various Security Patches

suse
Calendar Grey July 26, 2018
Dist Suse Esm H88
The latest patch for webkit2gtk3 resolves 7 vulnerabilities to enhance the security framework and safeguard systems from possible intrusions.
An update that fixes 7 vulnerabilities is now available

Summary

This update for webkit2gtk3 to version 2.20.3 fixes the following issues: These security issues were fixed: - CVE-2018-4190: An unspecified issue allowed remote attackers to obtain sensitive credential information that is transmitted during a CSS mask-image fetch (bsc#1097693). - CVE-2018-4199: An unspecified issue allowed remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site (bsc#1097693) - CVE-2018-4218: An unspecified issue allowed remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site that triggers an @generatorState use-after-free (bsc#1097693) - CVE-2018-4222: An unspecified issue allowed remote attackers to execute

References

#1095611 #1097693

Cross- CVE-2018-11646 CVE-2018-4190 CVE-2018-4199

CVE-2018-4218 CVE-2018-4222 CVE-2018-4232

CVE-2018-4233

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-11646.html

https://www.suse.com/security/cve/CVE-2018-4190.html

https://www.suse.com/security/cve/CVE-2018-4199.html

https://www.suse.com/security/cve/CVE-2018-4218.html

https://www.suse.com/security/cve/CVE-2018-4222.html

https://www.suse.com/security/cve/CVE-2018-4232.html

https://www.suse.com/security/cve/CVE-2018-4233.html

https://bugzilla.suse.com/1095611

https://bugzilla.suse.com/1097693

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2075-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here