Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE: 2021:1990-1 Important: Webkit2gtk3 Security Update

suse
Calendar Grey June 17, 2021
Scroller Suse
This Debian upgrade tackles significant vulnerabilities, correcting 14 safety flaws in libssl for improved defense.
An update that fixes 17 vulnerabilities is now available

Summary

This update for webkit2gtk3 fixes the following issues: - Update to version 2.32.1: + Improve handling of Media Capture devices. + Improve WebAudio playback. + Improve video orientation handling. + Improve seeking support for MSE playback. + Improve flush support in EME decryptors. + Fix HTTP status codes for requests done through a custom URI handler. + Fix the Bubblewrap sandbox in certain 32-bit systems. + Fix inconsistencies between the WebKitWebView.is-muted property state and values returned by webkit_web_view_is_playing_audio(). + Fix the build with ENABLE_VIDEO=OFF. + Fix wrong timestamps for long-lived cookies. + Fix UI process crash when failing to load favicons. + Fix several crashes and rendering issues. - Including Security fixes for: CVE-2021-1788, CVE-2021-1844,

References

#1177087 #1179122 #1179451 #1182286 #1184155

#1184262

Cross- CVE-2020-13543 CVE-2020-13558 CVE-2020-13584

CVE-2020-27918 CVE-2020-29623 CVE-2020-9947

CVE-2020-9948 CVE-2020-9951 CVE-2020-9983

CVE-2021-1765 CVE-2021-1788 CVE-2021-1789

CVE-2021-1799 CVE-2021-1801 CVE-2021-1844

CVE-2021-1870 CVE-2021-1871

CVSS scores:

CVE-2020-13543 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2020-13543 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2020-13558 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2020-13558 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2020-13584 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2020-13584 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1990-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.