Mageia 2023-0177: webkit2 security update
Summary
HTML document may be able to render iframes with sensitive user
information (CVE-2022-0108)
maliciously crafted web content may lead to arbitrary code execution.
(CVE-2022-32885)
use-after-free vulnerability exists in WebCore::RenderLayer. This issue
allows remote attackers to execute arbitrary code or cause a denial of
service (memory corruption and application crash) via a crafted web site.
(CVE-2023-25358)
maliciously crafted web content may bypass Same Origin Policy
(CVE-2023-27932)
Website may be able to track sensitive user information. Description: The
issue was addressed by removing origin information. (CVE-2023-27954)
maliciously crafted web content may lead to arbitrary code execution
(CVE-2023-28205)
References
- https://bugs.mageia.org/show_bug.cgi?id=31854
- https://webkitgtk.org/security/WSA-2023-0003.html
- https://webkitgtk.org/2023/04/20/webkitgtk2.38.6-released.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0108
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32885
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-25358
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27932
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27954
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28205
Resolution
MGASA-2023-0177 - Updated webkit2 packages fix security vulnerability
SRPMS
- 8/core/webkit2-2.38.6-1.mga8