Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues: - Expand lang sub-package in spec file unconditionally to handle previous name change from WebKit2GTK-lang to WebKitGTK-lang. This change affected the automatic generated Requires tag on WebKit2GTK-%{_apiver}, then getting out of sync of what's being required and what's being provided. Now, any sub-package that was providing WebKit2GTK-%{_apiver} will provide WebKitGTK-%{_apiver} instead (bsc#1214835, bsc#1214640, bsc#1214093). - Require libwaylandclient0 >= 1.20. 15.4 originally had 1.19.0, but webkitgtk uses a function added in 1.20.0, so we need to ensure that the wayland update is pulled in (bsc#1215072). - Update to version 2.40.5 (bsc#1213905 bsc#1213379 bsc#1213581 bsc#1215230): CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611, CVE-2023-40397, CVE-2023-37450, CVE-2023-28198, CVE-2023-32370
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for webkit2gtk3 fixes the following issues: - Expand lang sub-package in spec file unconditionally to handle previous name change from WebKit2GTK-lang to WebKitGTK-lang. This change affected the automatic generated Requires tag on WebKit2GTK-%{_apiver}, then getting out of sync of what's being required and what's being provided. Now, any sub-package that was providing WebKit2GTK-%{_apiver} will provide WebKitGTK-%{_apiver} instead (bsc#1214835, bsc#1214640, bsc#1214093). - Require libwaylandclient0 >= 1.20. 15.4 originally had 1.19.0, but webkitgtk uses a function added in 1.20.0, so we need to ensure that the wayland update is pulled in (bsc#1215072). - Update to version 2.40.5 (bsc#1213905 bsc#1213379 bsc#1213581 bsc#1215230): CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611, CVE-2023-40397, CVE-2023-37450, CVE-2023-28198, CVE-2023-32370
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1213379
- https://bugzilla.suse.com/1213581
- https://bugzilla.suse.com/1213905
- https://bugzilla.suse.com/1214093
- https://bugzilla.suse.com/1214640
- https://bugzilla.suse.com/1214835
- https://bugzilla.suse.com/1215072
- https://bugzilla.suse.com/1215230
- https://www.suse.com/security/cve/CVE-2023-28198
- https://www.suse.com/security/cve/CVE-2023-32370
- https://www.suse.com/security/cve/CVE-2023-37450
- https://www.suse.com/security/cve/CVE-2023-38594
- https://www.suse.com/security/cve/CVE-2023-38595
- https://www.suse.com/security/cve/CVE-2023-38597
- https://www.suse.com/security/cve/CVE-2023-38599
- https://www.suse.com/security/cve/CVE-2023-38600
- https://www.suse.com/security/cve/CVE-2023-38611
- https://www.suse.com/security/cve/CVE-2023-40397
- https://www.suse.com/support/update/announcement/2023/suse-su-20233753-1/