Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Ubuntu 12.04: 1524-1 Critical Advisory on WebKit Remote Attacks

ubuntu
Calendar Grey August 8, 2012
Scroller Ubuntu
Several vulnerabilities addressed in WebKit for Ubuntu 12.04 LTS, which could enable remote exploit attempts.
Multiple security vulnerabilities were fixed in WebKit.

Summary

Multiple security vulnerabilities were fixed in WebKit.

Software Description:

- webkit: Web content engine library for GTK+

Details:

A large number of security issues were discovered in the WebKit browser and

JavaScript engines. If a user were tricked into viewing a malicious

website, a remote attacker could exploit a variety of issues related to web

browser security, including cross-site scripting attacks, denial of

service attacks, and arbitrary code execution.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  libjavascriptcoregtk-1.0-0      1.8.1-0ubuntu0.12.04.1
  libjavascriptcoregtk-3.0-0      1.8.1-0ubuntu0.12.04.1
  libwebkitgtk-1.0-0              1.8.1-0ubuntu0.12.04.1
  libwebkitgtk-3.0-0              1.8.1-0ubuntu0.12.04.1

After a standard system update you need to restart your session to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-1524-1

CVE-2011-3046, CVE-2011-3050, CVE-2011-3067, CVE-2011-3068,

CVE-2011-3069, CVE-2011-3071, CVE-2011-3073, CVE-2011-3074,

CVE-2011-3075, CVE-2011-3078, CVE-2012-0672, CVE-2012-3615,

CVE-2012-3655, CVE-2012-3656, CVE-2012-3680, https://bugs.launchpad.net/ubuntu/+source/webkit/+bug/1027283

Severity
critical
Lowest
Low
Medium
High
Critical

August 08, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.