Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE Linux Enterprise 15-SP2: 2020:3867-1 Crucial Webkit2Gtk3 Security Fix

suse
Calendar Grey December 17, 2020
Scroller Suse
SUSE has released a critical security patch for webkit2gtk3 addressing five vulnerabilities that could lead to unauthorized code execution, thereby improving overall system security.
An update that fixes 5 vulnerabilities is now available

Summary

This update for webkit2gtk3 fixes the following issues: -webkit2gtk3 was updated to version 2.30.3 (bsc#1179122 bsc#1179451): - CVE-2021-13543: Fixed a use after free which could have led to arbitrary code execution. - CVE-2021-13584: Fixed a use after free which could have led to arbitrary code execution. - CVE-2021-9948: Fixed a type confusion which could have led to arbitrary code execution. - CVE-2021-9951: Fixed a use after free which could have led to arbitrary code execution. - CVE-2021-9983: Fixed an out of bounds write which could have led to arbitrary code execution. - Have the libwebkit2gtk package require libjavascriptcoregtk of the same version (bsc#1171531). - Enable c_loop on aarch64: currently needed for compilation to succeed with JIT disabled. Also disable sampling profiler, since it conflicts

References

#1171531 #1177087 #1179122 #1179451

Cross- CVE-2020-13543 CVE-2020-13584 CVE-2020-9948

CVE-2020-9951 CVE-2020-9983

Affected Products:

SUSE Linux Enterprise Module for Desktop Applications 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP2

https://www.suse.com/security/cve/CVE-2020-13543.html

https://www.suse.com/security/cve/CVE-2020-13584.html

https://www.suse.com/security/cve/CVE-2020-9948.html

https://www.suse.com/security/cve/CVE-2020-9951.html

https://www.suse.com/security/cve/CVE-2020-9983.html

https://bugzilla.suse.com/1171531

https://bugzilla.suse.com/1177087

https://bugzilla.suse.com/1179122

https://bugzilla.suse.com/1179451

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3867-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.