Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

UBUNTU: 2023:7892-3 critical vulnerability in libxml2 with escalation

suse
Calendar Grey November 24, 2023
Dist Suse Esm H88
Important WebKit2GTK3 upgrade for openSUSE addresses numerous critical security flaws, including potential remote code execution threats.
* bsc#1217210 Cross-References: * CVE-2022-32919 * CVE-2022-32933

Summary

## This update for webkit2gtk3 fixes the following issues: Update to version 2.42.2 (bsc#1217210): * CVE-2023-41983: Processing web content may lead to a denial-of-service. * CVE-2023-42852: Processing web content may lead to arbitrary code execution. Already previously fixed: * CVE-2022-32919: Visiting a website that frames malicious content may lead to UI spoofing (fixed already in 2.38.4). * CVE-2022-32933: A website may be able to track the websites a user visited in private browsing mode (fixed already in 2.38.0). * CVE-2022-46705: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4). * CVE-2022-46725: Visiting a malicious website may lead to address bar spoofing (fixed already in 2.38.4).

References

* bsc#1217210

Cross-

* CVE-2022-32919

* CVE-2022-32933

* CVE-2022-46705

* CVE-2022-46725

* CVE-2023-32359

* CVE-2023-41983

* CVE-2023-42852

CVSS scores:

* CVE-2022-46705 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

* CVE-2022-46705 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

* CVE-2022-46725 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

* CVE-2022-46725 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

* CVE-2023-32359 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-32359 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-41983 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-41983 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4561-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here