# Security update for webkit2gtk3

Announcement ID: SUSE-SU-2023:4294-1  
Rating: important  
References:

  * bsc#1214093
  * bsc#1214640
  * bsc#1214835
  * bsc#1215072
  * bsc#1215661
  * bsc#1215866
  * bsc#1215867
  * bsc#1215868
  * bsc#1215869
  * bsc#1215870
  * bsc#1216483

  
Cross-References:

  * CVE-2023-35074
  * CVE-2023-39434
  * CVE-2023-39928
  * CVE-2023-40451
  * CVE-2023-41074
  * CVE-2023-41993

  
CVSS scores:

  * CVE-2023-35074 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-35074 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-39434 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-39434 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-39928 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-39928 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-40451 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-40451 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-41074 ( SUSE ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-41074 ( NVD ):  8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  * CVE-2023-41993 ( SUSE ):  8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
  * CVE-2023-41993 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * Basesystem Module 15-SP4
  * Basesystem Module 15-SP5
  * Desktop Applications Module 15-SP4
  * Desktop Applications Module 15-SP5
  * Development Tools Module 15-SP4
  * Development Tools Module 15-SP5
  * openSUSE Leap 15.4
  * openSUSE Leap 15.5
  * SUSE Linux Enterprise Desktop 15 SP4
  * SUSE Linux Enterprise Desktop 15 SP5
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise Real Time 15 SP4
  * SUSE Linux Enterprise Real Time 15 SP5
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Manager Proxy 4.3
  * SUSE Manager Retail Branch Server 4.3
  * SUSE Manager Server 4.3

  
  
An update that solves six vulnerabilities and has five security fixes can now be
installed.

## Description:

This update for webkit2gtk3 ships missing Lang packages to SUSE Linux Enterprise
15 SP4 and SP5.

Security fixes:

  * CVE-2023-41993: Fixed an issue where processing malicious web content could
    have lead to arbitrary code execution (bsc#1215661).
  * CVE-2023-39928: Fixed a use-after-free that could be exploited to execute
    arbitrary code when visiting a malicious webpage (bsc#1215868).
  * CVE-2023-41074: Fixed an issue where processing malicious web content could
    have lead to arbitrary code execution (bsc#1215870).

Other fixes:

  * Fixed missing package dependencies (bsc#1215072).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * openSUSE Leap 15.4  
    zypper in -t patch SUSE-2023-4294=1 openSUSE-SLE-15.4-2023-4294=1

  * openSUSE Leap 15.5  
    zypper in -t patch openSUSE-SLE-15.5-2023-4294=1

  * Basesystem Module 15-SP4  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4294=1

  * Basesystem Module 15-SP5  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4294=1

  * Desktop Applications Module 15-SP4  
    zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-4294=1

  * Desktop Applications Module 15-SP5  
    zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-4294=1

  * Development Tools Module 15-SP4  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4294=1

  * Development Tools Module 15-SP5  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4294=1

## Package List:

  * openSUSE Leap 15.4 (noarch)
    * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2
    * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3
    * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2
  * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
    * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2
    * webkit2gtk4-minibrowser-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3
    * webkit2gtk3-devel-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2
    * webkitgtk-6_0-injected-bundles-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-6.0-2.42.1-150400.4.57.3
    * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-6_0-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3
    * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2
    * webkit2gtk4-minibrowser-2.42.1-150400.4.57.3
    * webkit-jsc-4-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit-6_0-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3
    * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2
    * webkit2gtk4-devel-2.42.1-150400.4.57.3
    * webkit2gtk3-soup2-minibrowser-2.42.1-150400.4.57.2
    * webkit-jsc-4-2.42.1-150400.4.57.2
    * webkit2gtk3-debugsource-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2
    * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3
    * typelib-1_0-WebKitWebProcessExtension-6_0-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3
    * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-4.1-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-minibrowser-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2
    * webkit2gtk3-minibrowser-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2
    * webkit2gtk4-debugsource-2.42.1-150400.4.57.3
    * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-6.0-debuginfo-2.42.1-150400.4.57.3
    * webkit-jsc-4.1-2.42.1-150400.4.57.2
    * webkit2gtk3-minibrowser-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2
  * openSUSE Leap 15.4 (x86_64)
    * libjavascriptcoregtk-4_1-0-32bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-32bit-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-32bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-32bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-32bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.42.1-150400.4.57.2
  * openSUSE Leap 15.4 (aarch64_ilp32)
    * libjavascriptcoregtk-4_1-0-64bit-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-64bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-64bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-64bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-64bit-2.42.1-150400.4.57.2
  * openSUSE Leap 15.5 (noarch)
    * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2
    * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3
    * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2
  * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
    * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2
    * webkit2gtk4-minibrowser-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3
    * webkit2gtk3-devel-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2
    * webkitgtk-6_0-injected-bundles-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-6.0-2.42.1-150400.4.57.3
    * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-6_0-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3
    * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2
    * webkit2gtk4-minibrowser-2.42.1-150400.4.57.3
    * webkit-jsc-4-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit-6_0-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3
    * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2
    * webkit2gtk4-devel-2.42.1-150400.4.57.3
    * webkit2gtk3-soup2-minibrowser-2.42.1-150400.4.57.2
    * webkit-jsc-4-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2
    * webkit2gtk3-debugsource-2.42.1-150400.4.57.2
    * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3
    * typelib-1_0-WebKitWebProcessExtension-6_0-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3
    * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-4.1-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-minibrowser-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2
    * webkit2gtk3-minibrowser-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2
    * webkit2gtk4-debugsource-2.42.1-150400.4.57.3
    * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2
    * webkit-jsc-6.0-debuginfo-2.42.1-150400.4.57.3
    * webkit-jsc-4.1-2.42.1-150400.4.57.2
    * webkit2gtk3-minibrowser-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2
  * openSUSE Leap 15.5 (x86_64)
    * libjavascriptcoregtk-4_1-0-32bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-32bit-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-32bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-32bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-32bit-2.42.1-150400.4.57.2
  * openSUSE Leap 15.5 (aarch64_ilp32)
    * libjavascriptcoregtk-4_1-0-64bit-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-64bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-64bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-64bit-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-64bit-2.42.1-150400.4.57.2
  * Basesystem Module 15-SP4 (noarch)
    * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2
  * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64)
    * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2
  * Basesystem Module 15-SP5 (noarch)
    * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2
  * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64)
    * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2
    * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2
  * Desktop Applications Module 15-SP4 (noarch)
    * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2
  * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64)
    * webkit2gtk3-debugsource-2.42.1-150400.4.57.2
    * webkit2gtk3-devel-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2
  * Desktop Applications Module 15-SP5 (noarch)
    * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2
  * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64)
    * webkit2gtk3-debugsource-2.42.1-150400.4.57.2
    * webkit2gtk3-devel-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2
    * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2
    * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2
    * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2
    * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2
  * Development Tools Module 15-SP4 (noarch)
    * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3
  * Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64)
    * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3
    * webkit2gtk4-debugsource-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3
    * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3
  * Development Tools Module 15-SP5 (noarch)
    * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3
  * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64)
    * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3
    * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3
    * webkit2gtk4-debugsource-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3
    * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3
    * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3

## References:

  * https://www.suse.com/security/cve/CVE-2023-35074.html
  * https://www.suse.com/security/cve/CVE-2023-39434.html
  * https://www.suse.com/security/cve/CVE-2023-39928.html
  * https://www.suse.com/security/cve/CVE-2023-40451.html
  * https://www.suse.com/security/cve/CVE-2023-41074.html
  * https://www.suse.com/security/cve/CVE-2023-41993.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1214093
  * https://bugzilla.suse.com/show_bug.cgi?id=1214640
  * https://bugzilla.suse.com/show_bug.cgi?id=1214835
  * https://bugzilla.suse.com/show_bug.cgi?id=1215072
  * https://bugzilla.suse.com/show_bug.cgi?id=1215661
  * https://bugzilla.suse.com/show_bug.cgi?id=1215866
  * https://bugzilla.suse.com/show_bug.cgi?id=1215867
  * https://bugzilla.suse.com/show_bug.cgi?id=1215868
  * https://bugzilla.suse.com/show_bug.cgi?id=1215869
  * https://bugzilla.suse.com/show_bug.cgi?id=1215870
  * https://bugzilla.suse.com/show_bug.cgi?id=1216483

openSUSE: 2023:4294-1: important: webkit2gtk3 Security Advisory Update

October 31, 2023
This update for webkit2gtk3 ships missing Lang packages to SUSE Linux Enterprise 15 SP4 and SP5

Description

This update for webkit2gtk3 ships missing Lang packages to SUSE Linux Enterprise 15 SP4 and SP5. Security fixes: * CVE-2023-41993: Fixed an issue where processing malicious web content could have lead to arbitrary code execution (bsc#1215661). * CVE-2023-39928: Fixed a use-after-free that could be exploited to execute arbitrary code when visiting a malicious webpage (bsc#1215868). * CVE-2023-41074: Fixed an issue where processing malicious web content could have lead to arbitrary code execution (bsc#1215870). Other fixes: * Fixed missing package dependencies (bsc#1215072).

 

Patch

## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4294=1 openSUSE-SLE-15.4-2023-4294=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4294=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4294=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4294=1 * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-4294=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-4294=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4294=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4294=1


Package List

* openSUSE Leap 15.4 (noarch) * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2 * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3 * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2 * webkit2gtk4-minibrowser-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3 * webkit2gtk3-devel-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-6.0-2.42.1-150400.4.57.3 * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-6_0-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3 * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2 * webkit2gtk4-minibrowser-2.42.1-150400.4.57.3 * webkit-jsc-4-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit-6_0-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3 * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2 * webkit2gtk4-devel-2.42.1-150400.4.57.3 * webkit2gtk3-soup2-minibrowser-2.42.1-150400.4.57.2 * webkit-jsc-4-2.42.1-150400.4.57.2 * webkit2gtk3-debugsource-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2 * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3 * typelib-1_0-WebKitWebProcessExtension-6_0-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3 * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-4.1-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-minibrowser-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2 * webkit2gtk3-minibrowser-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2 * webkit2gtk4-debugsource-2.42.1-150400.4.57.3 * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-6.0-debuginfo-2.42.1-150400.4.57.3 * webkit-jsc-4.1-2.42.1-150400.4.57.2 * webkit2gtk3-minibrowser-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2 * openSUSE Leap 15.4 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-32bit-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-32bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-32bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.42.1-150400.4.57.2 * openSUSE Leap 15.4 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-64bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-64bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-64bit-2.42.1-150400.4.57.2 * openSUSE Leap 15.5 (noarch) * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2 * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3 * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2 * webkit2gtk4-minibrowser-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3 * webkit2gtk3-devel-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-6.0-2.42.1-150400.4.57.3 * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-6_0-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3 * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2 * webkit2gtk4-minibrowser-2.42.1-150400.4.57.3 * webkit-jsc-4-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit-6_0-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3 * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2 * webkit2gtk4-devel-2.42.1-150400.4.57.3 * webkit2gtk3-soup2-minibrowser-2.42.1-150400.4.57.2 * webkit-jsc-4-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2 * webkit2gtk3-debugsource-2.42.1-150400.4.57.2 * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3 * typelib-1_0-WebKitWebProcessExtension-6_0-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3 * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-4.1-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-minibrowser-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2 * webkit2gtk3-minibrowser-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2 * webkit2gtk4-debugsource-2.42.1-150400.4.57.3 * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2 * webkit-jsc-6.0-debuginfo-2.42.1-150400.4.57.3 * webkit-jsc-4.1-2.42.1-150400.4.57.2 * webkit2gtk3-minibrowser-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2 * openSUSE Leap 15.5 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-32bit-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-32bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-32bit-2.42.1-150400.4.57.2 * openSUSE Leap 15.5 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-64bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-64bit-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-64bit-2.42.1-150400.4.57.2 * Basesystem Module 15-SP4 (noarch) * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2 * Basesystem Module 15-SP5 (noarch) * WebKitGTK-4.0-lang-2.42.1-150400.4.57.2 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKit2-4_0-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_0-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-devel-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-2.42.1-150400.4.57.2 * webkit2gtk3-soup2-debugsource-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_0-37-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_0-injected-bundles-2.42.1-150400.4.57.2 * Desktop Applications Module 15-SP4 (noarch) * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2 * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * webkit2gtk3-debugsource-2.42.1-150400.4.57.2 * webkit2gtk3-devel-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2 * Desktop Applications Module 15-SP5 (noarch) * WebKitGTK-4.1-lang-2.42.1-150400.4.57.2 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * webkit2gtk3-debugsource-2.42.1-150400.4.57.2 * webkit2gtk3-devel-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2WebExtension-4_1-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-2.42.1-150400.4.57.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.42.1-150400.4.57.2 * libwebkit2gtk-4_1-0-debuginfo-2.42.1-150400.4.57.2 * typelib-1_0-JavaScriptCore-4_1-2.42.1-150400.4.57.2 * typelib-1_0-WebKit2-4_1-2.42.1-150400.4.57.2 * Development Tools Module 15-SP4 (noarch) * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3 * Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3 * webkit2gtk4-debugsource-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3 * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3 * Development Tools Module 15-SP5 (noarch) * WebKitGTK-6.0-lang-2.42.1-150400.4.57.3 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-6_0-1-debuginfo-2.42.1-150400.4.57.3 * libjavascriptcoregtk-6_0-1-2.42.1-150400.4.57.3 * webkit2gtk4-debugsource-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-debuginfo-2.42.1-150400.4.57.3 * webkitgtk-6_0-injected-bundles-2.42.1-150400.4.57.3 * libwebkitgtk-6_0-4-2.42.1-150400.4.57.3


References

* bsc#1214093 * bsc#1214640 * bsc#1214835 * bsc#1215072 * bsc#1215661 * bsc#1215866 * bsc#1215867 * bsc#1215868 * bsc#1215869 * bsc#1215870 * bsc#1216483 ## References: * https://www.suse.com/security/cve/CVE-2023-35074.html * https://www.suse.com/security/cve/CVE-2023-39434.html * https://www.suse.com/security/cve/CVE-2023-39928.html * https://www.suse.com/security/cve/CVE-2023-40451.html * https://www.suse.com/security/cve/CVE-2023-41074.html * https://www.suse.com/security/cve/CVE-2023-41993.html * https://bugzilla.suse.com/show_bug.cgi?id=1214093 * https://bugzilla.suse.com/show_bug.cgi?id=1214640 * https://bugzilla.suse.com/show_bug.cgi?id=1214835 * https://bugzilla.suse.com/show_bug.cgi?id=1215072 * https://bugzilla.suse.com/show_bug.cgi?id=1215661 * https://bugzilla.suse.com/show_bug.cgi?id=1215866 * https://bugzilla.suse.com/show_bug.cgi?id=1215867 * https://bugzilla.suse.com/show_bug.cgi?id=1215868 * https://bugzilla.suse.com/show_bug.cgi?id=1215869 * https://bugzilla.suse.com/show_bug.cgi?id=1215870 * https://bugzilla.suse.com/show_bug.cgi?id=1216483


Severity
Announcement ID: SUSE-SU-2023:4294-1
Rating: important

Related News