ArchLinux: 202002-10: webkit2gtk: multiple issues
Summary
- CVE-2020-3862 (denial of service)
A malicious website may be able to cause a denial of service.
- CVE-2020-3864 (same-origin policy bypass)
A DOM object context may not have had a unique security origin.
- CVE-2020-3865 (sandbox escape)
A top-level DOM object context may have incorrectly been considered
secure.
- CVE-2020-3867 (cross-site scripting)
Processing maliciously crafted web content may lead to universal cross
site scripting.
- CVE-2020-3868 (arbitrary code execution)
Processing maliciously crafted web content may lead to arbitrary code
execution. Credit to Marcin Towalski of Cisco Talos.
Resolution
Upgrade to 2.26.4-1.
# pacman -Syu "webkit2gtk>=2.26.4-1"
The problems have been fixed upstream in version 2.26.4.
References
https://webkitgtk.org/security/WSA-2020-0002.html https://security.archlinux.org/CVE-2020-3862 https://security.archlinux.org/CVE-2020-3864 https://security.archlinux.org/CVE-2020-3865 https://security.archlinux.org/CVE-2020-3867 https://security.archlinux.org/CVE-2020-3868
Workaround
None.