WebKitGTK and WPE WebKit Security Advisory WSA-2020-0007

Carlos Alberto Lopez Perez <[email protected]> Wed, 29 Jul 2020 12:40:42 +0200
Newsgroups gmane.os.opendarwin.webkit.gtk,gmane.comp.security.oss.general,gmane.comp.security.bugtraq
Organization Igalia S.L.
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============1558303299==
Content-Type: multipart/signed; micalg=pgp-sha512;
 protocol="application/pgp-signature";
 boundary="T0lAS9E5P8G5AVPxHaCt6XxWPq6ntIMq0"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--T0lAS9E5P8G5AVPxHaCt6XxWPq6ntIMq0
Content-Type: multipart/mixed; boundary="cDQJSOfyNayXWCWoiJmuONDnL2UBPEudv"

--cDQJSOfyNayXWCWoiJmuONDnL2UBPEudv
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: quoted-printable

------------------------------------------------------------------------
WebKitGTK and WPE WebKit Security Advisory                 WSA-2020-0007
------------------------------------------------------------------------

Date reported           : July 29, 2020
Advisory ID             : WSA-2020-0007
WebKitGTK Advisory URL  : https://webkitgtk.org/security/WSA-2020-0007.ht=
ml
WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2020-0007.ht=
ml
CVE identifiers         : CVE-2020-9862, CVE-2020-9893, CVE-2020-9894,
                          CVE-2020-9895, CVE-2020-9915, CVE-2020-9925.

Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2020-9862
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to Ophir Lojkine (@lovasoa).
    Impact: Copying a URL from Web Inspector may lead to command
    injection. Description: A command injection issue existed in Web
    Inspector. This issue was addressed with improved escaping.

CVE-2020-9893
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to 0011 working with Trend Micro Zero Day Initiative.
    Impact: A remote attacker may be able to cause unexpected
    application termination or arbitrary code execution. Description: An
    use-after-free issue was addressed with improved memory management.

CVE-2020-9894
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to 0011 working with Trend Micro Zero Day Initiative.
    Impact: A remote attacker may be able to cause unexpected
    application termination or arbitrary code execution. Description: An
    out-of-bounds read was addressed with improved input validation.

CVE-2020-9895
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to Wen Xu of SSLab, Georgia Tech.
    Impact: A remote attacker may be able to cause unexpected
    application termination or arbitrary code execution. Description: An
    use-after-free issue was addressed with improved memory management.

CVE-2020-9915
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to Ayoub AIT ELMOKHTAR of Noon.
    Impact: Processing maliciously crafted web content may prevent
    Content Security Policy from being enforced. Description: An access
    issue existed in Content Security Policy.  This issue was addressed
    with improved access restrictions.

CVE-2020-9925
    Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28=
=2E4
    Credit to an anonymous researcher.
    Impact: Processing maliciously crafted web content may lead to
    universal cross site scripting. Description: A logic issue was
    addressed with improved state management.


We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.

Further information about WebKitGTK and WPE WebKit security advisories
can be found at: https://webkitgtk.org/security.html or
https://wpewebkit.org/security/.

The WebKitGTK and WPE WebKit team,
July 29, 2020


--cDQJSOfyNayXWCWoiJmuONDnL2UBPEudv--

--T0lAS9E5P8G5AVPxHaCt6XxWPq6ntIMq0
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Comment: You can fetch my GnuPG key from http://key.neutrino.es

iQIzBAEBCgAdFiEEtdK1C8SOx/HukNmrllCJzmuV+IIFAl8hUioACgkQllCJzmuV
+IIZww/+IGmWqk3IFIcguavB9zaYNm/LLRGe9gNpypwP8Wdd2p1XrAIpX9/KnWMV
QHlwfyiKed0WyCxsoOvAfLD5gOKsqiUzxqfR25Bw1D40O6zLjn9eXqe2R8JDELPS
9b5NM8O9RbFOvuhPxFB0rxHSShcZHbItDHOcuLvvxu1bg2tVQRz3w5Xcn2DPWhsm
JVTtBvxy0JzFGTm/j8hsLeBACJ/d6daF7cA95LBIhEqnPft0J3xoz5muLgcWiM5E
e9stTnHp8HQqt0Owkbf+g+qrWaCZODYhJN80otoUifIeEEAPbtA61xzZ5Gh4EYKn
JActNS8pEbUf5qmB/tKs2SDTvnv/1RwKZuf45RssL2z70kdRwBTrqGT7+kax64fC
w9K1qffZcircE/Nuc3+ggzeQfJh+dIV5TTloa2TNfQtOLbJEI90peLL0EFYhcs4J
qBjKZqyGU1fyFqO9eINl+tNAuAp9ZX6pmmY1YHpqm03ZKDcNqRykaJtVnhaFefrt
rKgfP8b/LQomH1GJTvIshEucQnKa1NjXh3ty8qNdMiDRmvxycDcP0d3fLkDgSp6c
Ib27BOTHMX7JblMlT/+Xic2vvCo7JQs8ETCHITIaM11YO/I0RDQpjRi0lmaa1zRP
0v6lTc0IAlVD6aJWOvoPI4J7gVK6JUhQ7RKJfrp1tU8rPO8yJy4=
=BEZj
-----END PGP SIGNATURE-----

--T0lAS9E5P8G5AVPxHaCt6XxWPq6ntIMq0--

--===============1558303299==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
webkit-gtk mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-gtk

--===============1558303299==--