Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE Linux 15-SP2: SUSE-SU-2022:0182-2 Important: Webkit2gtk3 Logic Flaws

suse
Calendar Grey February 17, 2022
Dist Suse Esm H88
An upgrade for webkit2gtk3 fixes 42 bugs, including critical security vulnerabilities. Ensure your system is protected by applying this update.
An update that fixes 43 vulnerabilities is now available

Summary

This update for webkit2gtk3 fixes the following issues: - Update to version 2.34.3 (bsc#1194019). - CVE-2021-30887: Fixed logic issue allowing unexpectedly unenforced Content Security Policy when processing maliciously crafted web content. - CVE-2021-30890: Fixed logic issue allowing universal cross site scripting when processing maliciously crafted web content. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-182=1 Package List: - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): libjavascriptcoregtk-4_0-18-2.34.3-23.3

References

#1194019

Cross- CVE-2019-8766 CVE-2019-8782 CVE-2019-8808

CVE-2019-8815 CVE-2020-13753 CVE-2020-27918

CVE-2020-29623 CVE-2020-3902 CVE-2020-9802

CVE-2020-9803 CVE-2020-9805 CVE-2020-9947

CVE-2020-9948 CVE-2020-9951 CVE-2020-9952

CVE-2021-1765 CVE-2021-1788 CVE-2021-1817

CVE-2021-1820 CVE-2021-1825 CVE-2021-1826

CVE-2021-1844 CVE-2021-1871 CVE-2021-30661

CVE-2021-30666 CVE-2021-30682 CVE-2021-30761

CVE-2021-30762 CVE-2021-30809 CVE-2021-30818

CVE-2021-30823 CVE-2021-30836 CVE-2021-30846

CVE-2021-30848 CVE-2021-30849 CVE-2021-30851

CVE-2021-30858 CVE-2021-30884 CVE-2021-30887

CVE-2021-30888 CVE-2021-30889 CVE-2021-30890

CVE-2021-30897

CVSS scores:

CVE-2019-8766 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0182-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here