Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

webkit2gtk: security update to 2.46.3 #8449

Open
MingcongBai opened this issue Oct 31, 2024 · 0 comments
Open

webkit2gtk: security update to 2.46.3 #8449

MingcongBai opened this issue Oct 31, 2024 · 0 comments
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@MingcongBai
Copy link
Member

MingcongBai commented Oct 31, 2024

Affected package (and version)

webkit2gtk < 2.46.3

CVE ID(s)

CVE-2024-44185, CVE-2024-44244, CVE-2024-44296

Severity

N/A

Other security advisory ID(s)

WSA-2024-0006

Description/References

CVE-2024-44185
Versions affected: WebKitGTK and WPE WebKit before 2.46.0.
Credit to Gary Kwong.
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash Description: The issue was addressed with
improved checks.
WebKit Bugzilla: 276097

CVE-2024-44244
Versions affected: WebKitGTK and WPE WebKit before 2.46.3.
Credit to an anonymous researcher, Q1IQ (@q1iqF) and P1umer (@P1umer).
Impact: Processing maliciously crafted web content may lead to an
unexpected process crash Description: A memory corruption issue was
addressed with improved input validation.
WebKit Bugzilla: 279780

CVE-2024-44296
Versions affected: WebKitGTK and WPE WebKit before 2.46.3.
Credit to Narendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd,
Pune (India).
Impact: Processing maliciously crafted web content may prevent
Content Security Policy from being enforced Description: The issue
was addressed with improved checks.
WebKit Bugzilla: 278765

Patch(es)/Solution(s)

Update to 2.46.3.

@MingcongBai MingcongBai added security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade labels Oct 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

1 participant