Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Ubuntu 22.04 & 23.04 USN-6264-1 Critical WebKitGTK Remote Threats

ubuntu
Calendar Grey July 31, 2023
Dist Ubuntu Esm H88
Multiple vulnerabilities addressed in WebKitGTK for Ubuntu versions 22.04 and 23.04. Users advised to upgrade to enhance security measures.
Several security issues were fixed in WebKitGTK.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in WebKitGTK. Software Description: - webkit2gtk: Web content engine library for GTK+ Details: Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: libjavascriptcoregtk-4.0-18 2.40.4-0ubuntu0.23.04.1 libjavascriptcoregtk-4.1-0 2.40.4-0ubuntu0.23.04.1 libjavascriptcoregtk-6.0-1 2.40.4-0ubuntu0.23.04.1 libwebkit2gtk-4.0-37 2.40.4-0ubuntu0.23.04.1 libwebkit2gtk-4.1-0 2.40.4-0ubuntu0.23.04.1 libwebkitgtk-6.0-4 2.40.4-0ubuntu0.23.04.1 Ubuntu 22.04 LTS: libjavascriptcoregtk-4.0-18 2.40.4-0ubuntu0.22.04.1 libjavascriptcoregtk-4.1-0 2.40.4-0ubuntu0.22.04.1 libjavascriptcoregtk-6.0-1 2.40.4-0ubuntu0.22.04.1 libwebkit2gtk-4.0-37 2.40.4-0ubuntu0.22.04.1 libwebkit2gtk-4.1-0 2.40.4-0ubuntu0.22.04.1 libwebkitgtk-6.0-4 2.40.4-0ubuntu0.22.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK, such as Epiphany, to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6264-1

CVE-2023-28204, CVE-2023-32373, CVE-2023-32393, CVE-2023-32435,

CVE-2023-32439, CVE-2023-37450

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6264-1

Package Information

https://launchpad.net/ubuntu/+source/webkit2gtk/2.40.4-0ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.40.4-0ubuntu0.22.04.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here