ALSA-2023:6535
Dashboard / Vulnerabilities / ALSA-2023:6535
ALSA-2023:6535
Summary: Important: webkit2gtk3 security and bug fix update
Details: WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Security Fix(es): * webkitgtk: arbitrary code execution (CVE-2023-32393) * webkitgtk: bypass Same Origin Policy (CVE-2023-38572) * webkitgtk: Processing web content may lead to arbitrary code execution (CVE-2023-38592) * webkitgtk: arbitrary code execution (CVE-2023-38594) * webkitgtk: arbitrary code execution (CVE-2023-38595) * webkitgtk: arbitrary code execution (CVE-2023-38597) * webkitgtk: arbitrary code execution (CVE-2023-38600) * webkitgtk: arbitrary code execution (CVE-2023-38611) * webkitgtk: Memory corruption issue when processing web content (CVE-2022-32885) * webkitgtk: Same Origin Policy bypass via crafted web content (CVE-2023-27932) * webkitgtk: Website may be able to track sensitive user information (CVE-2023-27954) * webkitgtk: use after free vulnerability (CVE-2023-28198) * webkitgtk: content security policy blacklist failure (CVE-2023-32370) * webkitgtk: disclose sensitive information (CVE-2023-38133) * webkitgtk: track sensitive user information (CVE-2023-38599) * webkitgtk: processing web content may lead to arbitrary code execution (CVE-2023-39434) * webkitgtk: arbitrary javascript code execution (CVE-2023-40397) * webkitgtk: attacker with JavaScript execution may be able to execute arbitrary code (CVE-2023-40451) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
References: https://access.redhat.com/errata/RHSA-2023:6535, https://access.redhat.com/security/cve/CVE-2022-32885, https://access.redhat.com/security/cve/CVE-2023-27932, https://access.redhat.com/security/cve/CVE-2023-27954, https://access.redhat.com/security/cve/CVE-2023-28198, https://access.redhat.com/security/cve/CVE-2023-32370, https://access.redhat.com/security/cve/CVE-2023-32393, https://access.redhat.com/security/cve/CVE-2023-38133, https://access.redhat.com/security/cve/CVE-2023-38572, https://access.redhat.com/security/cve/CVE-2023-38592, https://access.redhat.com/security/cve/CVE-2023-38594, https://access.redhat.com/security/cve/CVE-2023-38595, https://access.redhat.com/security/cve/CVE-2023-38597, https://access.redhat.com/security/cve/CVE-2023-38599, https://access.redhat.com/security/cve/CVE-2023-38600, https://access.redhat.com/security/cve/CVE-2023-38611, https://access.redhat.com/security/cve/CVE-2023-39434, https://access.redhat.com/security/cve/CVE-2023-40397, https://access.redhat.com/security/cve/CVE-2023-40451, https://bugzilla.redhat.com/2224608, https://bugzilla.redhat.com/2231015, https://bugzilla.redhat.com/2231017, https://bugzilla.redhat.com/2231018, https://bugzilla.redhat.com/2231019, https://bugzilla.redhat.com/2231020, https://bugzilla.redhat.com/2231021, https://bugzilla.redhat.com/2231022, https://bugzilla.redhat.com/2231028, https://bugzilla.redhat.com/2231043, https://bugzilla.redhat.com/2236842, https://bugzilla.redhat.com/2236843, https://bugzilla.redhat.com/2236844, https://bugzilla.redhat.com/2238943, https://bugzilla.redhat.com/2238944, https://bugzilla.redhat.com/2238945, https://bugzilla.redhat.com/2241405, https://bugzilla.redhat.com/2241409, https://errata.almalinux.org/9/ALSA-2023-6535.html
Affected packages
Package
Name: webkit2gtk3
Purl: pkg:rpm/almalinux/webkit2gtk3
Affected ranges
Type: ECOSYSTEM
Events:
