SUSE-SU-2023:3753-1
Dashboard / Vulnerabilities / SUSE-SU-2023:3753-1
SUSE-SU-2023:3753-1
Summary: Security update for webkit2gtk3
Details: This update for webkit2gtk3 fixes the following issues: - Expand lang sub-package in spec file unconditionally to handle previous name change from WebKit2GTK-lang to WebKitGTK-lang. This change affected the automatic generated Requires tag on WebKit2GTK-%{_apiver}, then getting out of sync of what's being required and what's being provided. Now, any sub-package that was providing WebKit2GTK-%{_apiver} will provide WebKitGTK-%{_apiver} instead (bsc#1214835, bsc#1214640, bsc#1214093). - Require libwaylandclient0 >= 1.20. 15.4 originally had 1.19.0, but webkitgtk uses a function added in 1.20.0, so we need to ensure that the wayland update is pulled in (bsc#1215072). - Update to version 2.40.5 (bsc#1213905 bsc#1213379 bsc#1213581 bsc#1215230): CVE-2023-38594, CVE-2023-38595, CVE-2023-38597, CVE-2023-38599, CVE-2023-38600, CVE-2023-38611, CVE-2023-40397, CVE-2023-37450, CVE-2023-28198, CVE-2023-32370
References: https://www.suse.com/support/update/announcement/2023/suse-su-20233753-1/, https://bugzilla.suse.com/1213379, https://bugzilla.suse.com/1213581, https://bugzilla.suse.com/1213905, https://bugzilla.suse.com/1214093, https://bugzilla.suse.com/1214640, https://bugzilla.suse.com/1214835, https://bugzilla.suse.com/1215072, https://bugzilla.suse.com/1215230, https://www.suse.com/security/cve/CVE-2023-28198, https://www.suse.com/security/cve/CVE-2023-32370, https://www.suse.com/security/cve/CVE-2023-37450, https://www.suse.com/security/cve/CVE-2023-38594, https://www.suse.com/security/cve/CVE-2023-38595, https://www.suse.com/security/cve/CVE-2023-38597, https://www.suse.com/security/cve/CVE-2023-38599, https://www.suse.com/security/cve/CVE-2023-38600, https://www.suse.com/security/cve/CVE-2023-38611, https://www.suse.com/security/cve/CVE-2023-40397
Affected packages
Package
Name: webkit2gtk3-soup2
Purl: pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
