Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE 15 SP3: 2024:1280-2 Critical: webkit2gtk3 Denial of Service

suse
Calendar Grey April 12, 2024
Dist Suse Esm H88
The recent advisory from SUSE concerning webkit2gtk3 addresses several critical vulnerabilities, improving overall system integrity and efficiency.

* bsc#1222010 Cross-References: * CVE-2023-42843 * CVE-2023-42950

Summary

## This update for webkit2gtk3 fixes the following issues: * CVE-2024-23252: Fixed denial of service via crafted web content (bsc#1222010). * CVE-2024-23254: Fixed possible audio data exilftration cross-origin via malicious website (bsc#1222010). * CVE-2024-23263: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). * CVE-2024-23280: Fixed possible user fingeprint via malicious crafted web content (bsc#1222010). * CVE-2024-23284: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). * CVE-2023-42950: Fixed arbitrary code execution via crafted web content (bsc#1222010). * CVE-2023-42956: Fixed denial of service via crafted web content (bsc#1222010).

References

* bsc#1222010

Cross-

* CVE-2023-42843

* CVE-2023-42950

* CVE-2023-42956

* CVE-2024-23252

* CVE-2024-23254

* CVE-2024-23263

* CVE-2024-23280

* CVE-2024-23284

CVSS scores:

* CVE-2023-42843 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

* CVE-2023-42950 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2023-42950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2023-42956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-42956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-23252 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-23254 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1269-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here