Security update for webkit2gtk3
This update for webkit2gtk3 fixes the following issues: - CVE-2023-42890: Fixed processing malicious web content may lead to arbitrary code execution (bsc#1218033). - CVE-2023-42883: Fixed processing a malicious image may lead to a denial-of-service (bsc#1218032). - CVE-2023-41074: Fixed use-after-free in the MediaRecorder API of the WebKit GStreamer-based ports (bsc#1215870). - CVE-2023-40451, CVE-2023-41074: Update to version 2.42.4 (bsc#1215868).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for webkit2gtk3 fixes the following issues: - CVE-2023-42890: Fixed processing malicious web content may lead to arbitrary code execution (bsc#1218033). - CVE-2023-42883: Fixed processing a malicious image may lead to a denial-of-service (bsc#1218032). - CVE-2023-41074: Fixed use-after-free in the MediaRecorder API of the WebKit GStreamer-based ports (bsc#1215870). - CVE-2023-40451, CVE-2023-41074: Update to version 2.42.4 (bsc#1215868).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1215868
- https://bugzilla.suse.com/1215870
- https://bugzilla.suse.com/1218032
- https://bugzilla.suse.com/1218033
- https://www.suse.com/security/cve/CVE-2023-32359
- https://www.suse.com/security/cve/CVE-2023-39928
- https://www.suse.com/security/cve/CVE-2023-41074
- https://www.suse.com/security/cve/CVE-2023-42883
- https://www.suse.com/security/cve/CVE-2023-42890
- https://www.suse.com/support/update/announcement/2024/suse-su-20240003-1/