Mageia 2023-0197: webkit2 security update
Summary
Out-of-bounds read (CVE-2023-28204)
Use-after-free issue (CVE-2023-32373)
References
- https://bugs.mageia.org/show_bug.cgi?id=31986
- https://support.apple.com/en-us/102735
- https://webkitgtk.org/security/WSA-2023-0004.html
- https://webkitgtk.org/2023/05/29/webkitgtk2.40.2-released.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28204
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32373
Resolution
MGASA-2023-0197 - Updated webkit2 packages fix security vulnerability
SRPMS
- 8/core/unifdef-2.12-1.mga8
- 8/core/libwpe-1.14.1-1.mga8
- 8/core/wpebackend-fdo-1.14.2-1.mga8
- 8/core/libavif-0.11.1-1.mga8
- 8/core/webkit2-2.40.2-1.mga8