Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 35: FEDORA-2021-db6ebb2d68 Critical: Webkit2gtk3 Security Update

Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK > = 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-db6ebb2d68 2021-10-29 22:48:33.394808 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.34.1 Release : 2.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK > = 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 23 2021 Michael Catanzaro 2.34.1-2 - Revert "Remove old obsoletes/provides" * Thu Oct 21 2021 Michael Catanzaro 2.34.1-1 - Update to 2.34.1 * Wed Sep 29 2021 Michael Catanzaro 2.34.0-4 - Improve instructions for generating GPG keyring * Wed Sep 29 2021 Michael Catanzaro 2.34.0-3 - Remove old obsoletes/provides * Thu Sep 23 2021 Michael Catanzaro 2.34.0-2 - Improve BuildRequires --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-db6ebb2d68' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Debian 11's patch 1.8.3 enhances libcurl with critical bug fixes and performance upgrades.. Webkit2gtk3 Update,Fedora 35 Patch,GTK Security Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 29, 2021 Critical Fedora
89

Fedora 35: 2022-9146cbf7f8 High: Webkit2gtk3 Update Notification

Update to WebKitGTK 2.32.0: * NPAPI plugins support have been removed. * System font scaling factor is correctly applied now. * New permission request API for MediaKeySystem access. * New API to remove individual scripts/stylesheets using WebKitUserContentManager. * Web inspector now shows detailed information about main loop frames. * The minimum required GStreamer. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8070916f7a 2021-03-29 00:14:59.219532 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 34 Version : 2.32.0 Release : 1.fc34 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to WebKitGTK 2.32.0: * NPAPI plugins support have been removed. * System font scaling factor is correctly applied now. * New permission request API for MediaKeySystem access. * New API to remove individual scripts/stylesheets using WebKitUserContentManager. * Web inspector now shows detailed information about main loop frames. * The minimum required GStreamer version is now 1.14. * The GStreamer runtime is now initialized only when required. * Improved platform support for WebAudio (WebAudio-> MediaStream, Worklet, Multi-channel). * Support for hardware-accelerated video rendering on i.MX8 platforms (using the NXP driver). Security fixes: CVE-2020-27918, CVE-2020-29623, CVE-2021-1765, CVE-2021-1788, CVE-2021-1789, CVE-2021-1799, CVE-2021-1801, CVE-2021-1844, CVE-2021-1870, CVE-2021-1871 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 26 2021 Michael Catanzaro - 2.32.0-1 - Updateto 2.32.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8070916f7a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora Release Announcement for webkit2gtk3 highlights significant modifications regarding access rights and interface revisions. Learn additional details.. WebKitGTK, Fedora Update, API Changes. . LinuxSecurity.com Team

Calendar 2 Mar 28, 2021 Fedora
89

Fedora 29: 2018-a1f37d2f08 Moderate: Webkit2gtk3 Memory Leak Resolution

This update addresses the following vulnerability: * [CVE-2018-4345](https://www.cve.org/CVERecord?id=CVE-2018-4345) This update brings the following changes: * Many improvements and fixes for video playback with media source extensions (MSE), which improve the user experience across the board, and in particular for playback of WebM videos. *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a1f37d2f08 2018-11-04 05:49:41.589645 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 29 Version : 2.22.3 Release : 1.fc29 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKit2 based WebKitGTK+ for GTK+ 3. --------------------------------------------------------------------------------Update Information: This update addresses the following vulnerability: * [CVE-2018-4345](https://www.cve.org/CVERecord?id=CVE-2018-4345) This update brings the following changes: * Many improvements and fixes for video playback with media source extensions (MSE), which improve the user experience across the board, and in particular for playback of WebM videos. * Fix a memory leak during media playback when using playbin3. * Fix portions of Web views not being rendered after resizing. * Fix Resource Timing reporting for iframe elements. * Fix the build with the remote Web Inspector disabled. * Fix the build on ARMv7 with NEON extensions. * Fix several crashes and rendering issues. --------------------------------------------------------------------------------ChangeLog: * Mon Oct 29 2018 Tomas Popela - 2.22.3-1 - Update to 2.22.3 * Fri Oct 19 2018 Tomas Popela - 2.22.2-2 - Fix WebProcess crash while printing - Resolves:rhbz#1639754 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a1f37d2f08' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This Ubuntu release resolves a vulnerability in libjpeg-turbo, improving image processing and eliminating data corruption.. Fedora Webkit2gtk3 Update, Security Patch, Media Playback Fixes, Memory Leak Resolution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 04, 2018 Important Fedora
89

Fedora 28: 2018-118b9abf99 Critical Update for Webkit2gtk3 Security Issues

This update addresses the following vulnerabilities: * [CVE-2018-4190](https://www.cve.org/CVERecord?id=CVE-2018-4190), [CVE-2018-4199](https://www.cve.org/CVERecord?id=CVE-2018-4199), [CVE-2018-4218](https://www.cve.org/CVERecord?id=CVE-2018-4218), [CVE-2018-4222](https://www.cve.org/CVERecord?id=CVE-2018-4222), . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-118b9abf99 2018-06-16 20:14:44.574740 -------------------------------------------------------------------------------- Name : webkit2gtk3 Product : Fedora 28 Version : 2.20.3 Release : 1.fc28 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKit2 based WebKitGTK+ for GTK+ 3. -------------------------------------------------------------------------------- Update Information: This update addresses the following vulnerabilities: * [CVE-2018-4190](https://www.cve.org/CVERecord?id=CVE-2018-4190), [CVE-2018-4199](https://www.cve.org/CVERecord?id=CVE-2018-4199), [CVE-2018-4218](https://www.cve.org/CVERecord?id=CVE-2018-4218), [CVE-2018-4222](https://www.cve.org/CVERecord?id=CVE-2018-4222), [CVE-2018-4232](https://www.cve.org/CVERecord?id=CVE-2018-4232), [CVE-2018-4233](https://www.cve.org/CVERecord?id=CVE-2018-4233), [CVE-2018-4246](https://www.cve.org/CVERecord?id=CVE-2018-4246), [CVE-2018-11646](https://www.cve.org/CVERecord?id=CVE-2018-11646). Additional fixes: * Fix installation directory of API documentation. * Disable Gigacage if mmap fails to allocate in Linux. * Add user agent quirk for paypal website. * Properly detect compiler flags, needed libs, and fallbacks for usage of 64-bit atomic operations. * Fix a network process crash when trying to get cookies of about:blank page. * Fix UI process crash when closing the window under Wayland. * Fix several crashesand rendering issues. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 11 2018 Tomas Popela - 2.20.3-1 - Update to 2.20.3 * Wed May 9 2018 Tomas Popela - 2.20.2-1 - Update to 2.20.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-118b9abf99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/GY5NYBUZRNA46WQEP2XZCOJFY4BVEJ3X/ . This Ubuntu 20.04 patch addresses crucial gnome-shell vulnerabilities, boosting overall system security and performance.. Fedora 28 Update, Webkit2gtk3 Security, Linux Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 16, 2018 Critical Fedora
89

Fedora 24 WebKitGTK4 Security Update 2016-f4b5897686 Moderate

Update WebKitGTK+ package to 2.14.1. Major changes in 2.14.0: * Threaded compositor is enabled by default in both X11 and Wayland. * Accelerated compositing is now supported in Wayland. * Clipboard works in Wayland too. * Memory pressure handler always works even when cgroups is not present or not configured. * The HTTP disk cache implements speculative revalidation of. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f4b5897686 2016-10-18 11:22:09.730738 -------------------------------------------------------------------------------- Name : webkitgtk4 Product : Fedora 24 Version : 2.14.1 Release : 1.fc24 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKitGTK+ for GTK+ 3. -------------------------------------------------------------------------------- Update Information: Update WebKitGTK+ package to 2.14.1. Major changes in 2.14.0: * Threaded compositor is enabled by default in both X11 and Wayland. * Accelerated compositing is now supported in Wayland. * Clipboard works in Wayland too. * Memory pressure handler always works even when cgroups is not present or not configured. * The HTTP disk cache implements speculative revalidation of resources. * DRI3 is no longer a problem when using the modesetting intel driver. * The amount of file descriptors that are kept open has been drastically reduced. Fixes from 2.14.1: * MiniBrowser and jsc binaries are now installed in pkglibexecdir instead of bindir. * Improve performance when resizing a window with multiple web views in X11. * Check whether GDK can use GL before using gdk_cairo_draw_from_gl() in Wayland. * Updated default UserAgent string or better compatibility. * Fix a crash on github.com in IntlDateTimeFormat::resolvedOptions when using the C locale. * Fix BadDamage X errors when closing the webview in X11. * Fix UIProcess crash when using Japanese input method. * Fix build with clang due to missing header includes. * Fix the build with USE_REDIRECTED_XCOMPOSITE_WINDOW disabled. * Fix several crashes and rendering issues. * Translation updates: German. Update Epiphany to be compatible with the new WebKitGTK+ package. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update webkitgtk4' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Elevate WebKitGTK+ to version 2.14.1 on Fedora 24, featuring enhanced compositing capabilities, refined clipboard functionality, and optimized memory management.. webkitgtk update,Fedora security,Fedora package update,GTK+ enhancements,system performance improvements. . LinuxSecurity.com Team

Calendar 2 Oct 18, 2016 Fedora
89

Fedora 23: FEDORA-2016-5d6d75dbea Critical Webkitgtk Security Fix

This update addresses the following vulnerabilities: * [CVE-2015-1120](https://www.cve.org/CVERecord?id=CVE-2015-1120) * [CVE-2015-1076](https://www.cve.org/CVERecord?id=CVE-2015-1076) * [CVE-2015-1071](https://www.cve.org/CVERecord?id=CVE-2015-1071) * [CVE-2015-1081](https://www.cve.org/CVERecord?id=CVE-2015-1081) *. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5d6d75dbea 2016-03-22 15:54:44.506688 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 23 Version : 2.4.10 Release : 1.fc23 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. -------------------------------------------------------------------------------- Update Information: This update addresses the following vulnerabilities: * [CVE-2015-1120](https://www.cve.org/CVERecord?id=CVE-2015-1120) * [CVE-2015-1076](https://www.cve.org/CVERecord?id=CVE-2015-1076) * [CVE-2015-1071](https://www.cve.org/CVERecord?id=CVE-2015-1071) * [CVE-2015-1081](https://www.cve.org/CVERecord?id=CVE-2015-1081) * [CVE-2015-1122](https://www.cve.org/CVERecord?id=CVE-2015-1122) * [CVE-2015-1155](https://www.cve.org/CVERecord?id=CVE-2015-1155) * [CVE-2014-1748](https://www.cve.org/CVERecord?id=CVE-2014-1748) * [CVE-2015-3752](https://www.cve.org/CVERecord?id=CVE-2015-3752) * [CVE-2015-5809](https://www.cve.org/CVERecord?id=CVE-2015-5809) * [CVE-2015-5928](https://www.cve.org/CVERecord?id=CVE-2015-5928) * [CVE-2015-3749](https://www.cve.org/CVERecord?id=CVE-2015-3749) * [CVE-2015-3659](https://www.cve.org/CVERecord?id=CVE-2015-3659) * [CVE-2015-3748](https://www.cve.org/CVERecord?id=CVE-2015-3748) * [CVE-2015-3743](https://www.cve.org/CVERecord?id=CVE-2015-3743) * [CVE-2015-3731](https://www.cve.org/CVERecord?id=CVE-2015-3731) * [CVE-2015-3745](https://www.cve.org/CVERecord?id=CVE-2015-3745) * [CVE-2015-5822](https://www.cve.org/CVERecord?id=CVE-2015-5822) * [CVE-2015-3658](https://www.cve.org/CVERecord?id=CVE-2015-3658) * [CVE-2015-3741](https://www.cve.org/CVERecord?id=CVE-2015-3741) * [CVE-2015-3727](https://www.cve.org/CVERecord?id=CVE-2015-3727) * [CVE-2015-5801](https://www.cve.org/CVERecord?id=CVE-2015-5801) * [CVE-2015-5788](https://www.cve.org/CVERecord?id=CVE-2015-5788) * [CVE-2015-3747](https://www.cve.org/CVERecord?id=CVE-2015-3747) * [CVE-2015-5794](https://www.cve.org/CVERecord?id=CVE-2015-5794) * [CVE-2015-1127](https://www.cve.org/CVERecord?id=CVE-2015-1127) * [CVE-2015-1153](https://www.cve.org/CVERecord?id=CVE-2015-1153) * [CVE-2015-1083](https://www.cve.org/CVERecord?id=CVE-2015-1083) Additional fixes: * Fix crashes on PowerPC 64. * Fix the build on PowerPC 32. * Add ARM64 build support. Translation updates * German * Spanish * French * Italian * Korean * Brazilian Portuguese * Russian * Chinese. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update webkitgtk' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . This patch addresses several vulnerabilities in webkitgtk for Fedora 23, enhancing both reliability and protection.. webkitgtk Update,Fedora Security,Web Rendering Engine,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 22, 2016 Critical Fedora
87

Debian: DSA-2188-1 Critical: WebKit Remote Memory Corruption

Several vulnerabilities have been discovered in webkit, a Web content engine library for Gtk+. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2188-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano March 10, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2010-1783 CVE-2010-2901 CVE-2010-4199 CVE-2010-4040 CVE-2010-4492 CVE-2010-4493 CVE-2010-4577 CVE-2010-4578 CVE-2010-0474 CVE-2011-0482 CVE-2011-0778 Several vulnerabilities have been discovered in webkit, a Web content engine library for Gtk+. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1783 WebKit does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document. CVE-2010-2901 The rendering implementation in WebKit allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. CVE-2010-4199 WebKit does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document. CVE-2010-4040 WebKit does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image. CVE-2010-4492 Use-after-free vulnerability in WebKit allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations. CVE-2010-4493 Use-after-free vulnerability in Webkit allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events CVE-2010-4577 The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion." CVE-2010-4578 WebKit does not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers." CVE-2011-0482 WebKit does not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document CVE-2011-0778 WebKit does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors. For the stable distribution (squeeze), these problems have been fixed in version 1.2.7-0+squeeze1 For the testing distribution (wheezy), and the unstable distribution (sid), these problems have been fixed in version 1.2.7-1 Security support for WebKit has been discontinued for the oldstable distribution (lenny). The current version in oldstable is not supported by upstream anymore and is affected by several security issues. Backporting fixes for these and any future issues has become unfeasible and therefore we need to drop our security support for the version in oldstable. We recommend that you upgrade your webkit packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at:http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple issues in WebKit resolved in Debian: DSA-2188-1. It is advised to upgrade for enhanced security and stability.. Debian Security Advisory, WebKit Memory Issue, Remote Attack Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 10, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here