Important: webkit2gtk3 security and bug fix update
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * webkitgtk: arbitrary code execution (CVE-2023-32393) * webkitgtk: bypass Same Origin Policy (CVE-2023-38572) * webkitgtk: Processing web content may lead to arbitrary code execution (CVE-2023-38592) * webkitgtk: arbitrary code execution (CVE-2023-38594) * webkitgtk: arbitrary code execution (CVE-2023-38595) * webkitgtk: arbitrary code execution (CVE-2023-38597) * webkitgtk: arbitrary code execution (CVE-2023-38600) * webkitgtk: arbitrary code execution (CVE-2023-38611) * webkitgtk: Memory corruption issue when processing web content (CVE-2022-32885) * webkitgtk: Same Origin Policy bypass via crafted web content (CVE-2023-27932) * webkitgtk: Website may be able to track sensitive user information (CVE-2023-27954) * webkitgtk: use after free vulnerability (CVE-2023-28198) * webkitgtk: content security policy blacklist failure (CVE-2023-32370) * webkitgtk: disclose sensitive information (CVE-2023-38133) * webkitgtk: track sensitive user information (CVE-2023-38599) * webkitgtk: processing web content may lead to arbitrary code execution (CVE-2023-39434) * webkitgtk: arbitrary javascript code execution (CVE-2023-40397) * webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code (CVE-2023-40451) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * webkitgtk: arbitrary code execution (CVE-2023-32393) * webkitgtk: bypass Same Origin Policy (CVE-2023-38572) * webkitgtk: Processing web content may lead to arbitrary code execution (CVE-2023-38592) * webkitgtk: arbitrary code execution (CVE-2023-38594) * webkitgtk: arbitrary code execution (CVE-2023-38595) * webkitgtk: arbitrary code execution (CVE-2023-38597) * webkitgtk: arbitrary code execution (CVE-2023-38600) * webkitgtk: arbitrary code execution (CVE-2023-38611) * webkitgtk: Memory corruption issue when processing web content (CVE-2022-32885) * webkitgtk: Same Origin Policy bypass via crafted web content (CVE-2023-27932) * webkitgtk: Website may be able to track sensitive user information (CVE-2023-27954) * webkitgtk: use after free vulnerability (CVE-2023-28198) * webkitgtk: content security policy blacklist failure (CVE-2023-32370) * webkitgtk: disclose sensitive information (CVE-2023-38133) * webkitgtk: track sensitive user information (CVE-2023-38599) * webkitgtk: processing web content may lead to arbitrary code execution (CVE-2023-39434) * webkitgtk: arbitrary javascript code execution (CVE-2023-40397) * webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code (CVE-2023-40451) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2023:7055
- https://access.redhat.com/security/cve/CVE-2022-32885
- https://access.redhat.com/security/cve/CVE-2023-27932
- https://access.redhat.com/security/cve/CVE-2023-27954
- https://access.redhat.com/security/cve/CVE-2023-28198
- https://access.redhat.com/security/cve/CVE-2023-32370
- https://access.redhat.com/security/cve/CVE-2023-32393
- https://access.redhat.com/security/cve/CVE-2023-38133
- https://access.redhat.com/security/cve/CVE-2023-38572
- https://access.redhat.com/security/cve/CVE-2023-38592
- https://access.redhat.com/security/cve/CVE-2023-38594
- https://access.redhat.com/security/cve/CVE-2023-38595
- https://access.redhat.com/security/cve/CVE-2023-38597
- https://access.redhat.com/security/cve/CVE-2023-38599
- https://access.redhat.com/security/cve/CVE-2023-38600
- https://access.redhat.com/security/cve/CVE-2023-38611
- https://access.redhat.com/security/cve/CVE-2023-39434
- https://access.redhat.com/security/cve/CVE-2023-40397
- https://access.redhat.com/security/cve/CVE-2023-40451
- https://bugzilla.redhat.com/2224608
- https://bugzilla.redhat.com/2231015
- https://bugzilla.redhat.com/2231017
- https://bugzilla.redhat.com/2231018
- https://bugzilla.redhat.com/2231019
- https://bugzilla.redhat.com/2231020
- https://bugzilla.redhat.com/2231021
- https://bugzilla.redhat.com/2231022
- https://bugzilla.redhat.com/2231028
- https://bugzilla.redhat.com/2231043
- https://bugzilla.redhat.com/2236842
- https://bugzilla.redhat.com/2236843
- https://bugzilla.redhat.com/2236844
- https://bugzilla.redhat.com/2238943
- https://bugzilla.redhat.com/2238944
- https://bugzilla.redhat.com/2238945
- https://bugzilla.redhat.com/2241405
- https://bugzilla.redhat.com/2241409
- https://errata.almalinux.org/8/ALSA-2023-7055.html