Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2024:1270-1 important: webkit2gtk3 denial of service issue

suse
Calendar Grey April 12, 2024
Dist Suse Esm H88
WebKitGTK3 security patches target severe flaws in various SUSE versions, offering detailed guidance for implementation.

* bsc#1222010 Cross-References: * CVE-2023-42843 * CVE-2023-42950

Summary

## This update for webkit2gtk3 fixes the following issues: * CVE-2024-23252: Fixed denial of service via crafted web content (bsc#1222010). * CVE-2024-23254: Fixed possible audio data exilftration cross-origin via malicious website (bsc#1222010). * CVE-2024-23263: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). * CVE-2024-23280: Fixed possible user fingeprint via malicious crafted web content (bsc#1222010). * CVE-2024-23284: Fixed lack of Content Security Policy enforcing via malicious crafted web content (bsc#1222010). * CVE-2023-42950: Fixed arbitrary code execution via crafted web content (bsc#1222010). * CVE-2023-42956: Fixed denial of service via crafted web content (bsc#1222010).

References

* bsc#1222010

Cross-

* CVE-2023-42843

* CVE-2023-42950

* CVE-2023-42956

* CVE-2024-23252

* CVE-2024-23254

* CVE-2024-23263

* CVE-2024-23280

* CVE-2024-23284

CVSS scores:

* CVE-2023-42843 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

* CVE-2023-42950 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2023-42950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2023-42956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-42956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-23252 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2024-23254 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1270-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here