Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-5934

WebkitGTK+: Multiple vulnerabilities [ GLSA 201812-04 ]

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed Earlier
    • Icon: Normal Normal
    • None
    • None
    • None

      Severity: Normal
      Title: WebkitGTK+: Multiple vulnerabilities
      Date: December 02, 2018
      Bugs: #667892
      ID: 201812-04

      • - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

      Synopsis
      ========

      Multiple vulnerabilities have been found in WebKitGTK+, the worst of
      which may lead to arbitrary code execution.

      Background
      ==========

      WebKitGTK+ is a full-featured port of the WebKit rendering engine,
      suitable for projects requiring any kind of web integration, from
      hybrid HTML/CSS applications to full-fledged web browsers.

      Affected packages
      =================

      -------------------------------------------------------------------
      Package / Vulnerable / Unaffected
      -------------------------------------------------------------------
      1 net-libs/webkit-gtk < 2.22.0 >= 2.22.0

      Description
      ===========

      Multiple vulnerabilities have been discovered in WebKitGTK+. Please
      review the referenced CVE identifiers for details.

      Impact
      ======

      A remote attacker could execute arbitrary commands or cause a Denial of
      Service condition via maliciously crafted web content.

      Workaround
      ==========

      There is no known workaround at this time.

      Resolution
      ==========

      All WebkitGTK+ users should upgrade to the latest version:

      1. emerge --sync
      2. emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.22.0"

      References
      ==========

      [ 1 ] CVE-2018-4191
      https://nvd.nist.gov/vuln/detail/CVE-2018-4191
      [ 2 ] CVE-2018-4197
      https://nvd.nist.gov/vuln/detail/CVE-2018-4197
      [ 3 ] CVE-2018-4207
      https://nvd.nist.gov/vuln/detail/CVE-2018-4207
      [ 4 ] CVE-2018-4208
      https://nvd.nist.gov/vuln/detail/CVE-2018-4208
      [ 5 ] CVE-2018-4209
      https://nvd.nist.gov/vuln/detail/CVE-2018-4209
      [ 6 ] CVE-2018-4210
      https://nvd.nist.gov/vuln/detail/CVE-2018-4210
      [ 7 ] CVE-2018-4212
      https://nvd.nist.gov/vuln/detail/CVE-2018-4212
      [ 8 ] CVE-2018-4213
      https://nvd.nist.gov/vuln/detail/CVE-2018-4213
      [ 9 ] CVE-2018-4299
      https://nvd.nist.gov/vuln/detail/CVE-2018-4299
      [ 10 ] CVE-2018-4306
      https://nvd.nist.gov/vuln/detail/CVE-2018-4306
      [ 11 ] CVE-2018-4309
      https://nvd.nist.gov/vuln/detail/CVE-2018-4309
      [ 12 ] CVE-2018-4311
      https://nvd.nist.gov/vuln/detail/CVE-2018-4311
      [ 13 ] CVE-2018-4312
      https://nvd.nist.gov/vuln/detail/CVE-2018-4312
      [ 14 ] CVE-2018-4314
      https://nvd.nist.gov/vuln/detail/CVE-2018-4314
      [ 15 ] CVE-2018-4315
      https://nvd.nist.gov/vuln/detail/CVE-2018-4315
      [ 16 ] CVE-2018-4316
      https://nvd.nist.gov/vuln/detail/CVE-2018-4316
      [ 17 ] CVE-2018-4317
      https://nvd.nist.gov/vuln/detail/CVE-2018-4317
      [ 18 ] CVE-2018-4318
      https://nvd.nist.gov/vuln/detail/CVE-2018-4318
      [ 19 ] CVE-2018-4319
      https://nvd.nist.gov/vuln/detail/CVE-2018-4319
      [ 20 ] CVE-2018-4323
      https://nvd.nist.gov/vuln/detail/CVE-2018-4323
      [ 21 ] CVE-2018-4328
      https://nvd.nist.gov/vuln/detail/CVE-2018-4328
      [ 22 ] CVE-2018-4358
      https://nvd.nist.gov/vuln/detail/CVE-2018-4358
      [ 23 ] CVE-2018-4359
      https://nvd.nist.gov/vuln/detail/CVE-2018-4359
      [ 24 ] CVE-2018-4361
      https://nvd.nist.gov/vuln/detail/CVE-2018-4361

      Availability
      ============

      This GLSA and any updates to it are available for viewing at
      the Gentoo Security Website:

      https://security.gentoo.org/glsa/201812-04

            oleg oleg
            palica Pavol Cupka
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: