WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004
Carlos Alberto Lopez Perez <[email protected]> Thu, 16 Apr 2020 14:10:59 +0200
| Newsgroups | gmane.comp.security.oss.general,gmane.os.opendarwin.webkit.gtk,gmane.comp.security.bugtraq |
|---|---|
| Organization | Igalia S.L. |
| Message-ID | <[email protected]> |
--M16bXE2ODwAcw4tINo43ly3mqjBL3dC9I Content-Type: multipart/mixed; boundary="qQ10skvrSJTSBq7Fpvt5d24f4XXVnyWwy"; protected-headers="v1" From: Carlos Alberto Lopez Perez <[email protected]> To: [email protected], [email protected] Cc: [email protected], [email protected], [email protected], bugtraq-o7tR/nIX9Vi1EmJ4MpGYnQC/[email protected] Message-ID: <fd936e74-01a4-b9df-1b50-733293493ec9-wEGTBA9jqPzQT0dZR+AlfA@public.gmane.org> Subject: WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004 --qQ10skvrSJTSBq7Fpvt5d24f4XXVnyWwy Content-Type: text/plain; charset=utf-8 Content-Language: en-GB Content-Transfer-Encoding: quoted-printable ------------------------------------------------------------------------ WebKitGTK and WPE WebKit Security Advisory WSA-2020-0004 ------------------------------------------------------------------------ Date reported : April 16, 2020 Advisory ID : WSA-2020-0004 WebKitGTK Advisory URL : https://webkitgtk.org/security/WSA-2020-0004.ht= ml WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2020-0004.ht= ml CVE identifiers : CVE-2020-11793. Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. CVE-2020-11793 Versions affected: WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1. Credit to Cim Stordal of Cognite. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or application crash (denial of service). Description: A memory corruption issue (use-after-free) was addressed with improved memory handling. We recommend updating to the latest stable versions of WebKitGTK and WPE WebKit. It is the best way to ensure that you are running safe versions of WebKit. Please check our websites for information about the latest stable releases. Further information about WebKitGTK and WPE WebKit security advisories can be found at: https://webkitgtk.org/security.html or https://wpewebkit.org/security/. The WebKitGTK and WPE WebKit team, April 16, 2020 --qQ10skvrSJTSBq7Fpvt5d24f4XXVnyWwy-- --M16bXE2ODwAcw4tINo43ly3mqjBL3dC9I Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- Comment: You can fetch my GnuPG key from http://key.neutrino.es iQIzBAEBCgAdFiEEtdK1C8SOx/HukNmrllCJzmuV+IIFAl6YS1MACgkQllCJzmuV +IJwsA/+NZmPiW6BbZfDhsHxu+OK060FNZ8ub4r9eZqjfs6rxOfOlLoN3+vtBXjn J5a/pZCmANmpkblrEmxdEG7uUTindJNY50g8VdnGLL5vdZBw5mtV/kNDc7AhJroT 7UkBj2C/tt/E0nHKhZ3LhEJlM3iqddECWSX06nv1IryYiyftM14e3iyFvIfQEGDD yN0LYBJn9NpbxRxQevlrxqqrBQd8KmuBsydJoINmP8sBrtPdwTG0q/1yadUREm7f d45k/HR2l3w1rnzf5FqtpTdEWmFWOhGcPNtFqMRReKKDY5ulu9BmIU1XjtS8Uudw 56mIy5hwjA89/l9VkLZ7RvBzuw3kVRurwWLRriQVvuHEX6gS2v8sbH6W9PmQJZ1Y h0/sXhSWLNGcD5ru5JrpGntWzUswYuL3b8/8c6qGHQzPJPpKJr3kX6y5DdvGypyy 7fOxLJyZHVDDgo/Up1WiJAfOG3fPJI/xRbZxr+OQlV14VcbDXHNkABYONDReR4h0 oFahkYdyzRQs0Co4fIJhtF0Onvw0fJhrjqZYyCN6X6Sc4RI0xnFmvuJA82lCZc0B v67T+/fbwWwh/xMZtTDHoqIGV0OJyf+Tl4jS4lDAGWw+4A8o1kv7y4nCOUktNgWn 3IGx/ZwPrnnerXrJV1e/ROpZfNQ5fXsqhxgChJPkhJNC8Jauxnc= =8+CJ -----END PGP SIGNATURE----- --M16bXE2ODwAcw4tINo43ly3mqjBL3dC9I--