[DSA 5937-1] webkit2gtk security update

Alberto Garcia <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5937-1                   [email protected]
https://www.debian.org/security/                           Alberto Garcia
June 06, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : webkit2gtk
CVE ID         : CVE-2025-24223 CVE-2025-31204 CVE-2025-31205 CVE-2025-31206
                 CVE-2025-31215 CVE-2025-31257

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2025-24223

    rheza and an anonymous researcher discovered that processing
    maliciously crafted web content may lead to memory corruption.

CVE-2025-31204

    Nan Wang discovered that processing maliciously crafted web
    content may lead to memory corruption.

CVE-2025-31205

    Ivan Fratric discovered that a malicious website may exfiltrate
    data cross-origin.

CVE-2025-31206

    An anonymous researcher discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

CVE-2025-31215

    Jiming Wang and Jikai Ren discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

CVE-2025-31257

    Juergen Schmied discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.

For the stable distribution (bookworm), these problems have been fixed in
version 2.48.3-1~deb12u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmhCqUUACgkQAAyEYu0C
2AJ2gQ//R1NV6wEfOQmpep5KelBGtDpoyw4WudfGDoR7T48Ckl3IcdpbBgHLmXS8
8RN0RumNXNNl6tuE4jTVWwIAwukCbEshQaN46aECwolfXI/MJr1tN3yUuZzsGXoC
2QhOO1cWkeX8cAxJJOjac7zIrK4rmaW5NXVYkzfSjZvgC5QadQrGYt9GDuJoyca0
scVDt5CuqlA991kg9ZgZR0Gni6W6eDA7LPWa4fgoy82yMOq5f9nXf0XZq6cHj/X0
3vMC+P9AH/aPyCfHZZhRhXTxb4AGfpiaZmFjsngsrdxoGGVkMMn+i8sUscythaOL
q2Nkgl5ZHOx2F0ImJpVgqwrs3aWUjIk5O4whfWNAlr9+mpUlYoLtHpxW2vsXXCrn
uLCxJ8r3iq+nlUICbYRxxjUvEm/IczUkOEepjqL0r2bGsS2bj7k8xlkUWx9kvq+q
NYuQulxkuMWnHmBeRwEoUZINhqu1z8uIMDrPi6RYcy3QIrLRnIU0Q6zZq8QBKPOa
AGkusl9HpTkgIXMx6gjA9Kv1MPaJObu5tswyEDivum1+dMVwWwYwOQA6NpjktV2G
Vf4D2GYbHnnjLNs1DYbzihvT7Wcynm1WPUBVaEwFdljdCkE3vY6TEDpWosPDRHdN
grgou0IYw9iokqFPSNtG8OQHLnK7mHEurmUGt4S7b5uBpeFAzyA=
=AzUD
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.