Alerts This Week
Warning Icon 1 775
Alerts This Week
Warning Icon 1 775

SUSE: 2022:0703-1 Important: Critical Execution Risks in Webkit2gtk3

suse
Calendar Grey March 3, 2022
Dist Suse Esm H88
An essential Ubuntu patch resolves 12 security flaws in gnome-shell, tackling risks related to memory leaks and code execution vulnerabilities.
An update that fixes 15 vulnerabilities is now available

Summary

This update for webkit2gtk3 fixes the following issues: Update to version 2.34.6 (bsc#1196133): - CVE-2022-22620: Processing maliciously crafted web content may have lead to arbitrary code execution. Update to version 2.34.5 (bsc#1195735): - CVE-2022-22589: A validation issue was addressed with improved input sanitization. - CVE-2022-22590: A use after free issue was addressed with improved memory management. - CVE-2022-22592: A logic issue was addressed with improved state management. Update to version 2.34.4 (bsc#1195064): - CVE-2021-30934: A buffer overflow issue was addressed with improved memory handling. - CVE-2021-30936: A use after free issue was addressed with improved memory management. - CVE-2021-30951: A use after free issue was addressed with improved memory management.

References

#1195064 #1195735 #1196133

Cross- CVE-2021-30934 CVE-2021-30936 CVE-2021-30951

CVE-2021-30952 CVE-2021-30953 CVE-2021-30954

CVE-2021-30984 CVE-2021-45481 CVE-2021-45482

CVE-2021-45483 CVE-2022-22589 CVE-2022-22590

CVE-2022-22592 CVE-2022-22594 CVE-2022-22620

CVSS scores:

CVE-2021-30934 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-30934 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-30936 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-30936 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-30951 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-30951 (SUSE): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0703-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here