WebKitGTK and WPE WebKit Security Advisory WSA-2020-0003
Carlos Alberto Lopez Perez <[email protected]> Thu, 12 Mar 2020 18:52:34 +0100
| Newsgroups | gmane.comp.security.oss.general,gmane.os.opendarwin.webkit.gtk,gmane.comp.security.bugtraq |
|---|---|
| Organization | Igalia S.L. |
| Message-ID | <[email protected]> |
--Qzuuh9dIO2dcjg2SamQG2D8tPZ6XJHR6o Content-Type: multipart/mixed; boundary="gKFYxh7PJc630pv3omI6EaENt9t6UOe9d"; protected-headers="v1" From: Carlos Alberto Lopez Perez <[email protected]> To: [email protected], [email protected] Cc: [email protected], [email protected], [email protected], bugtraq-o7tR/nIX9Vi1EmJ4MpGYnQC/[email protected] Message-ID: <9d9dcfba-7dae-4d99-e036-86a1ad7ed4cb-wEGTBA9jqPzQT0dZR+AlfA@public.gmane.org> Subject: WebKitGTK and WPE WebKit Security Advisory WSA-2020-0003 --gKFYxh7PJc630pv3omI6EaENt9t6UOe9d Content-Type: text/plain; charset=utf-8 Content-Language: en-GB Content-Transfer-Encoding: quoted-printable ------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2020-0003 ------------------------------------------------------------------------ Date reported : March 12, 2020 Advisory ID : WSA-2020-0003 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2020-0003.ht= ml WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2020-0003.ht= ml CVE identifiers : CVE-2020-10018. Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. CVE-2020-10018 Versions affected: WebKitGTK before 2.28.0 and WPE WebKit before 2.28.0. Credit to Sudhakar Verma, Ashfaq Ansari & Siddhant Badhe - Project Srishti of CloudFuzz. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A memory corruption issue (use-after-free) was addressed with improved memory handling. We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases. Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security/. The WebKitGTK and WPE WebKit team, March 12, 2020 --gKFYxh7PJc630pv3omI6EaENt9t6UOe9d-- --Qzuuh9dIO2dcjg2SamQG2D8tPZ6XJHR6o Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: You can fetch my GnuPG key from http://key.neutrino.es iQIzBAEBCgAdFiEEtdK1C8SOx/HukNmrllCJzmuV+IIFAl5qduIACgkQllCJzmuV +IJvMQ/5AV8MJvJKCGEVfm1b61tnEEy2Xdonj5g9Gf8Sd54gfM9PFM4bK2qbmZKv v8TgfteLz0giLCBFfkfcpOcuz2CCEGehX6ZvqZg5GJFLfAFmuFBRFzJ0xyKIS6fH YCHvRlJKTmAm8xX/cSN+GstZ5LVIJQsuKHeNUI5kkZSh+XtNqjF+1NpCmF11clT1 vrrQC3kCWLYw+SPezSWl0ef2atOpXJu1uTwbuD1IkfbT+lahSm31POJNV+chhx2F kiyQkZCG58x1YU6lkhseSbT6fxM3u9MilCg1KqzoDhleXkueed9X8HC8d3Ga1UBf /wJKBPamdM81251KfcN8txo6HCyxD5pICe4XihaO8UwTNcUtoPYtDctFIw285rkA QNe695J/FX5jr6eSbwp3w7DFkL3bWkufRCQUjLQdgwTKtAr3DYhLPjBeq7f9nME0 3P50Zayuxw9tlqRuMRbH11IzmPeD+wZnIMsLCkgy5sVWqFaR9wbYyr+pU8l+tx16 iZH3JU/f4cmtGGwJPXtKSpRTt4bqAySbmzWDwxsywZYtEUEtsUNt5KWkbGnBimlF YePEG6V/W+3sEHtmRkauBhlqMQSFKds9dwVdc1NS/SxfhXVa207gsezj/EMRify/ MzVbQ14k/3UFoIZ1xS07G8rW+2SSIzcuXSpaELa1Xm1yLt64OJM= =hNdz -----END PGP SIGNATURE----- --Qzuuh9dIO2dcjg2SamQG2D8tPZ6XJHR6o--