Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues: Update to version 2.38.3: - CVE-2022-42856: Fixed a potential arbitrary code execution when processing maliciously crafted web content (bsc#1206474). - CVE-2022-42852: Fixed disclosure of process memory by improved memory handling. - CVE-2022-42867: Fixed a use after free issue was addressed with improved memory management. - CVE-2022-46692: Fixed bypass of Same Origin Policy through improved state management. - CVE-2022-46698: Fixed disclosure of sensitive user information with improved checks. - CVE-2022-46699: Fixed an arbitrary code execution caused by memory corruption. - CVE-2022-46700: Fixed an arbitrary code execution caused by memory corruption.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for webkit2gtk3 fixes the following issues: Update to version 2.38.3: - CVE-2022-42856: Fixed a potential arbitrary code execution when processing maliciously crafted web content (bsc#1206474). - CVE-2022-42852: Fixed disclosure of process memory by improved memory handling. - CVE-2022-42867: Fixed a use after free issue was addressed with improved memory management. - CVE-2022-46692: Fixed bypass of Same Origin Policy through improved state management. - CVE-2022-46698: Fixed disclosure of sensitive user information with improved checks. - CVE-2022-46699: Fixed an arbitrary code execution caused by memory corruption. - CVE-2022-46700: Fixed an arbitrary code execution caused by memory corruption.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1206474
- https://bugzilla.suse.com/1206750
- https://www.suse.com/security/cve/CVE-2022-42852
- https://www.suse.com/security/cve/CVE-2022-42856
- https://www.suse.com/security/cve/CVE-2022-42863
- https://www.suse.com/security/cve/CVE-2022-42867
- https://www.suse.com/security/cve/CVE-2022-46691
- https://www.suse.com/security/cve/CVE-2022-46692
- https://www.suse.com/security/cve/CVE-2022-46698
- https://www.suse.com/security/cve/CVE-2022-46699
- https://www.suse.com/security/cve/CVE-2022-46700
- https://www.suse.com/support/update/announcement/2022/suse-su-20224642-1/