Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2018:2752-1 Moderate: Webkit2gtk3 Security Update

suse
Calendar Grey September 19, 2018
Dist Suse Esm H88
The recent SUSE Security Patch tackles 14 vulnerabilities in webkit2gtk3, bolstering application reliability and maintaining system security.
An update that fixes 14 vulnerabilities is now available

Summary

This update for webkit2gtk3 to version 2.20.5 fixes the following issues: Security issue fixed: - CVE-2018-12911: Fix off-by-one in xdg_mime_get_simple_globs (bsc#1101999). - CVE-2018-4261, CVE-2018-4262, CVE-2018-4263, CVE-2018-4264, CVE-2018-4265, CVE-2018-4267, CVE-2018-4272, CVE-2018-4284: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling. - CVE-2018-4266: A malicious website may be able to cause a denial of service. A race condition was addressed with additional validation. - CVE-2018-4270, CVE-2018-4271, CVE-2018-4273: Processing maliciously crafted web content may lead to an unexpected application crash. A memory corruption issue was addressed with improved input validation.

References

#1101999 #1104169

Cross- CVE-2018-12911 CVE-2018-4261 CVE-2018-4262

CVE-2018-4263 CVE-2018-4264 CVE-2018-4265

CVE-2018-4266 CVE-2018-4267 CVE-2018-4270

CVE-2018-4271 CVE-2018-4272 CVE-2018-4273

CVE-2018-4278 CVE-2018-4284

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-12911.html

https://www.suse.com/security/cve/CVE-2018-4261.html

https://www.suse.com/security/cve/CVE-2018-4262.html

https://www.suse.com/security/cve/CVE-2018-4263.html

https://www.suse.com/security/cve/CVE-2018-4264.html

https://www.suse.com/security/cve/CVE-2018-4265.html

https://www.suse.com/security/cve/CVE-2018-4266.html

Announcement ID: SUSE-SU-2018:2752-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here