Important: webkit2gtk3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:3713", "synopsis": "Important: webkit2gtk3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for webkit2gtk3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-44192)\n\n* webkitgtk: A malicious website may exfiltrate data cross-origin (CVE-2024-54467)\n\n* webkitgtk: Processing web content may lead to a denial-of-service (CVE-2024-54551)\n\n* webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack (CVE-2025-24208)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-24209)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-24216)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-30427)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2353871", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2353871", "description": ""}, {"ticket": "2353872", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2353872", "description": ""}, {"ticket": "2357909", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357909", "description": ""}, {"ticket": "2357910", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2357910", "description": ""}, {"ticket": "2357911", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357911", "description": ""}, {"ticket": "2357917", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357917", "description": ""}, {"ticket": "2357919", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357919", "description": ""}], "cves": [{"name": "CVE-2024-44192", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-44192", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-20"}, {"name": "CVE-2024-54467", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-54467", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "cvss3BaseScore": "6.5", "cwe": "CWE-200"}, {"name": "CVE-2024-54551", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-54551", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-119"}, {"name": "CVE-2025-24208", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24208", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-79"}, {"name": "CVE-2025-24209", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24209", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2025-24216", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24216", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-119"}, {"name": "CVE-2025-30427", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-30427", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore":"8.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2025-07-29T13:40:19.644888Z", "rpms": {"Rocky Linux 9": {"nvras": ["webkit2gtk3-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.src.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.x86_64.rpm","webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical patches for webkit2gtk3 on Rocky Linux released to address vulnerabilities that could lead to sensitive data leaks and service disruptions.. webkit2gtk3 update, Rocky Linux security, web content vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:2919-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:2919.html Issue date: 2016-12-07 CVE Names: CVE-2016-5203 CVE-2016-5204 CVE-2016-5205 CVE-2016-5206 CVE-2016-5207 CVE-2016-5208 CVE-2016-5209 CVE-2016-5210 CVE-2016-5211 CVE-2016-5212 CVE-2016-5213 CVE-2016-5214 CVE-2016-5215 CVE-2016-5216 CVE-2016-5217 CVE-2016-5218 CVE-2016-5219 CVE-2016-5220 CVE-2016-5221 CVE-2016-5222 CVE-2016-5223 CVE-2016-5224 CVE-2016-5225 CVE-2016-5226 CVE-2016-9650 CVE-2016-9651 CVE-2016-9652 ==================================================================== 1. Summary: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). This update upgrades Chromium to version55.0.2883.75. Security Fix(es): * Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2016-5203, CVE-2016-5204, CVE-2016-5205, CVE-2016-5206, CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5210, CVE-2016-5211, CVE-2016-5212, CVE-2016-5213, CVE-2016-9651, CVE-2016-9652, CVE-2016-5214, CVE-2016-5215, CVE-2016-5216, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219, CVE-2016-5220, CVE-2016-5221, CVE-2016-5222, CVE-2016-5223, CVE-2016-5224, CVE-2016-5225, CVE-2016-5226, CVE-2016-9650) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Chromium must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1400850 - CVE-2016-9651 chromium-browser: private property access in v8 1400851 - CVE-2016-5208 chromium-browser: universal xss in blink 1400852 - CVE-2016-5207 chromium-browser: universal xss in blink 1400853 - CVE-2016-5206 chromium-browser: same-origin bypass in pdfium 1400854 - CVE-2016-5205 chromium-browser: universal xss in blink 1400855 - CVE-2016-5204 chromium-browser: universal xss in blink 1400856 - CVE-2016-5209 chromium-browser: out of bounds write in blink 1400857 - CVE-2016-5203 chromium-browser: use after free in pdfium 1400859 - CVE-2016-5210 chromium-browser: out of bounds write in pdfium 1400861 - CVE-2016-5212 chromium-browser: local file disclosure in devtools 1400862 - CVE-2016-5211 chromium-browser: use after free in pdfium 1400863 - CVE-2016-5213 chromium-browser: use after free in v8 1400864 - CVE-2016-5214 chromium-browser: file download protection bypass 1400865 - CVE-2016-5216 chromium-browser: use after free in pdfium 1400866 - CVE-2016-5215 chromium-browser: use after free in webaudio 1400867 - CVE-2016-5217 chromium-browser: use ofunvalidated data in pdfium 1400868 - CVE-2016-5218 chromium-browser: address spoofing in omnibox 1400869 - CVE-2016-5219 chromium-browser: use after free in v8 1400870 - CVE-2016-5221 chromium-browser: integer overflow in angle 1400871 - CVE-2016-5220 chromium-browser: local file access in pdfium 1400872 - CVE-2016-5222 chromium-browser: address spoofing in omnibox 1400873 - CVE-2016-9650 chromium-browser: csp referrer disclosure 1400875 - CVE-2016-5223 chromium-browser: integer overflow in pdfium 1400876 - CVE-2016-5226 chromium-browser: limited xss in blink 1400877 - CVE-2016-5225 chromium-browser: csp bypass in blink 1400878 - CVE-2016-5224 chromium-browser: same-origin bypass in svg 1400879 - CVE-2016-9652 chromium-browser: various fixes from internal audits 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2016-5203 https://access.redhat.com/security/cve/CVE-2016-5204 https://access.redhat.com/security/cve/CVE-2016-5205 https://access.redhat.com/security/cve/CVE-2016-5206 https://access.redhat.com/security/cve/CVE-2016-5207 https://access.redhat.com/security/cve/CVE-2016-5208 https://access.redhat.com/security/cve/CVE-2016-5209 https://access.redhat.com/security/cve/CVE-2016-5210 https://access.redhat.com/security/cve/CVE-2016-5211 https://access.redhat.com/security/cve/CVE-2016-5212 https://access.redhat.com/security/cve/CVE-2016-5213 https://access.redhat.com/security/cve/CVE-2016-5214 https://access.redhat.com/security/cve/CVE-2016-5215 https://access.redhat.com/security/cve/CVE-2016-5216 https://access.redhat.com/security/cve/CVE-2016-5217 https://access.redhat.com/security/cve/CVE-2016-5218 https://access.redhat.com/security/cve/CVE-2016-5219 https://access.redhat.com/security/cve/CVE-2016-5220 https://access.redhat.com/security/cve/CVE-2016-5221 https://access.redhat.com/security/cve/CVE-2016-5222 https://access.redhat.com/security/cve/CVE-2016-5223 https://access.redhat.com/security/cve/CVE-2016-5224 https://access.redhat.com/security/cve/CVE-2016-5225 https://access.redhat.com/security/cve/CVE-2016-5226 https://access.redhat.com/security/cve/CVE-2016-9650 https://access.redhat.com/security/cve/CVE-2016-9651 https://access.redhat.com/security/cve/CVE-2016-9652 https://access.redhat.com/security/updates/classification/#important https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYSGRcXlSAg2UNWIIRAiHmAJ9Nl7uHXgQUjZU81KybHyCCHmCi8QCgr8fs CEnkb1YITLftO/cJ3o/KLWA=cu2B -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Updated chromium-browser packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security and bug fix update Advisory ID: RHSA-2015:0921-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2015:0921.html Issue date: 2015-04-30 CVE Names: CVE-2015-1243 CVE-2015-1250 ==================================================================== 1. Summary: Updated chromium-browser packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash or, potentially, execute arbitrary code with the privileges of the user running Chromium. (CVE-2015-1243, CVE-2015-1250) This update also fixes the following bug: * Prior to this update, Chromium did not accept GNOME's system proxy settings due to having GConf support disabled. This issue has beenresolved in this update. (BZ#1217065) All Chromium users should upgrade to these updated packages, which contain Chromium version 42.0.2311.135, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1216920 - CVE-2015-1243 chromium-browser: use-after-free in DOM 1216921 - CVE-2015-1250 chromium-browser: various unspecified flaws 1217065 - Chromium-browser not accepting gnome system proxy settings in RHEL6. 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2015-1243 https://access.redhat.com/security/cve/CVE-2015-1250 https://access.redhat.com/security/updates/classification/#important https://chromereleases.googleblog.com/2015/04/stable-channel-update_28.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVQopnXlSAg2UNWIIRAgQLAKCzVoixHduhi3H16D16uWNNhvdvcQCgqNj0 LvRH19/Se7OKiVYg1eoWKXA=+RnW -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Critical: firefox security update. Date: Wed, 31 Mar 2010 17:06:44 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL4.x i386/x86_64 Comments: To: "
Critical: firefox security update. Date: Wed, 4 Feb 2009 14:09:04 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL4.x, SL5.x i386/x86_64 Comments: To: "
Critical: firefox security update. Date: Fri, 8 Feb 2008 14:21:06 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for firefox on SL4.x, SL5.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.