Revision Date: | 2021-08-03 | Version: | 1 |
Title: | Security update for webkit2gtk3 (Important) |
Description: |
This update for webkit2gtk3 fixes the following issues:
- Update to version 2.32.3: - CVE-2021-21775: Fixed a use-after-free vulnerability in the way certain events are processed for ImageLoader objects. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability. (bsc#1188697) - CVE-2021-21779: Fixed a use-after-free vulnerability in the way that WebKit GraphicsContext handles certain events. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability. (bsc#1188697) - CVE-2021-30663: An integer overflow was addressed with improved input validation. (bsc#1188697) - CVE-2021-30665: A memory corruption issue was addressed with improved state management. (bsc#1188697) - CVE-2021-30689: A logic issue was addressed with improved state management. (bsc#1188697) - CVE-2021-30720: A logic issue was addressed with improved restrictions. (bsc#1188697) - CVE-2021-30734: Multiple memory corruption issues were addressed with improved memory handling. (bsc#1188697) - CVE-2021-30744: A cross-origin issue with iframe elements was addressed with improved tracking of security origins. (bsc#1188697) - CVE-2021-30749: Multiple memory corruption issues were addressed with improved memory handling. (bsc#1188697) - CVE-2021-30758: A type confusion issue was addressed with improved state handling. (bsc#1188697) - CVE-2021-30795: A use after free issue was addressed with improved memory management. (bsc#1188697) - CVE-2021-30797: This issue was addressed with improved checks. (bsc#1188697) - CVE-2021-30799: Multiple memory corruption issues were addressed with improved memory handling. (bsc#1188697)
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1128140 1135727 1135729 1171863 1171864 1171866 1172348 1188697 CVE-2019-12209 CVE-2019-12210 CVE-2019-9578 CVE-2020-10543 CVE-2020-10878 CVE-2020-12723 CVE-2021-21775 CVE-2021-21779 CVE-2021-30663 CVE-2021-30665 CVE-2021-30689 CVE-2021-30720 CVE-2021-30734 CVE-2021-30744 CVE-2021-30749 CVE-2021-30758 CVE-2021-30795 CVE-2021-30797 CVE-2021-30799 SUSE-SU-2019:1750-1 SUSE-SU-2020:1682-1 SUSE-SU-2021:2598-1
|
Platform(s): | SUSE Linux Enterprise Desktop 15 SP3 SUSE Linux Enterprise High Performance Computing 15 SP3 SUSE Linux Enterprise Module for Desktop Applications 15 SP3 SUSE Linux Enterprise Module for Development Tools 15 SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 SUSE Linux Enterprise Server 15 SP3 SUSE Linux Enterprise Server for SAP Applications 15 SP3 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Module for Development Tools 15 SP1 is installed AND Package Information
perl-5.26.1-7.12 is installed
OR perl-doc-5.26.1-7.12 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP1 is installed
AND Package Information
libu2f-host-1.1.6-3.6 is installed
OR libu2f-host-doc-1.1.6-3.6 is installed
OR u2f-host-1.1.6-3.6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Desktop Applications 15 SP3 is installed
AND Package Information
typelib-1_0-JavaScriptCore-4_0-2.32.3-9.1 is installed
OR typelib-1_0-WebKit2-4_0-2.32.3-9.1 is installed
OR typelib-1_0-WebKit2WebExtension-4_0-2.32.3-9.1 is installed
OR webkit2gtk3-devel-2.32.3-9.1 is installed
|