ArchLinux: 201505-19: webkitgtk2: man-in-the-middle
Summary
It was found that WebKitGTK+ version performed TLS certificate
verification too late, after sending an HTTP request rather than before.
This issue allows a man-in-the-middle attack to possibly gain sensitive
information.
Resolution
Upgrade to 2.4.9-1.
# pacman -Syu "webkitgtk2>=2.4.9-1"
The problem has been fixed upstream in version 2.4.9.
References
https://www.openwall.com/lists/oss-security/2015/03/18/4 https://access.redhat.com/security/cve/CVE-2015-2330 https://bugs.archlinux.org/task/44237
![Dist Arch](/images/distros/dist-arch.png)
Workaround
None.