Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE: 2024:1293-1 Important: Fixing Webkit2gtk3 Denial Of Service Threat

suse
Calendar Grey April 15, 2024
Dist Suse Esm H88
SUSE's Security Notice SUSE-SU-2024:1294-1 related to gnome-shell tackling essential vulnerabilities along with installation guidelines.

* bsc#1222010 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5

Summary

## webkit2gtk3 was updated to fix the following issues: Update to version 2.44.0 (boo#1222010): * CVE-2024-23252: Credit to anbu1024 of SecANT. Impact: Processing web content may lead to a denial-of-service. The issue was addressed with improved memory handling. * CVE-2024-23254: Credit to James Lee (@Windowsrcer). Impact: A malicious website may exfiltrate audio data cross-origin. The issue was addressed with improved UI handling. * CVE-2024-23263: Credit to Johan Carlsson (joaxcar). Impact: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. A logic issue was addressed with improved validation. * CVE-2024-23280: Credit to An anonymous researcher. Impact: A maliciously crafted webpage may be

References

* bsc#1222010

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

* SUSE Linux Enterprise Software Development Kit 12 SP5

* SUSE Linux Enterprise Workstation Extension 12 12-SP5

An update that has one security fix can now be installed.

##

* https://bugzilla.suse.com/show_bug.cgi?id=1222010

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1293-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here