[ GLSA 202208-39 ] WebKitGTK+: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <166199009828.12.9496266521302596456@ec95405eafab>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202208-39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: WebKitGTK+: Multiple Vulnerabilities
     Date: August 31, 2022
     Bugs: #866494, #864427, #856445, #861740, #837305, #845252, #839984, #833568, #832990
       ID: 202208-39

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in WebkitGTK+, the worst of
which could result in the arbitrary execution of code.

Background
==========

WebKitGTK+ is a full-featured port of the WebKit rendering engine,
suitable for projects requiring any kind of web integration, from hybrid
HTML/CSS applications to full-fledged web browsers.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /     Vulnerable     /            Unaffected
    -------------------------------------------------------------------
  1  net-libs/webkit-gtk        < 2.36.7                    >= 2.36.7

Description
===========

Multiple vulnerabilities have been discovered in WebKitGTK+. Please
review the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All WebKitGTK+ users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.36.7"

References
==========

[ 1 ] CVE-2022-2294
      https://nvd.nist.gov/vuln/detail/CVE-2022-2294
[ 2 ] CVE-2022-22589
      https://nvd.nist.gov/vuln/detail/CVE-2022-22589
[ 3 ] CVE-2022-22590
      https://nvd.nist.gov/vuln/detail/CVE-2022-22590
[ 4 ] CVE-2022-22592
      https://nvd.nist.gov/vuln/detail/CVE-2022-22592
[ 5 ] CVE-2022-22620
      https://nvd.nist.gov/vuln/detail/CVE-2022-22620
[ 6 ] CVE-2022-22624
      https://nvd.nist.gov/vuln/detail/CVE-2022-22624
[ 7 ] CVE-2022-22628
      https://nvd.nist.gov/vuln/detail/CVE-2022-22628
[ 8 ] CVE-2022-22629
      https://nvd.nist.gov/vuln/detail/CVE-2022-22629
[ 9 ] CVE-2022-22662
      https://nvd.nist.gov/vuln/detail/CVE-2022-22662
[ 10 ] CVE-2022-22677
      https://nvd.nist.gov/vuln/detail/CVE-2022-22677
[ 11 ] CVE-2022-26700
      https://nvd.nist.gov/vuln/detail/CVE-2022-26700
[ 12 ] CVE-2022-26709
      https://nvd.nist.gov/vuln/detail/CVE-2022-26709
[ 13 ] CVE-2022-26710
      https://nvd.nist.gov/vuln/detail/CVE-2022-26710
[ 14 ] CVE-2022-26716
      https://nvd.nist.gov/vuln/detail/CVE-2022-26716
[ 15 ] CVE-2022-26717
      https://nvd.nist.gov/vuln/detail/CVE-2022-26717
[ 16 ] CVE-2022-26719
      https://nvd.nist.gov/vuln/detail/CVE-2022-26719
[ 17 ] CVE-2022-30293
      https://nvd.nist.gov/vuln/detail/CVE-2022-30293
[ 18 ] CVE-2022-30294
      https://nvd.nist.gov/vuln/detail/CVE-2022-30294
[ 19 ] CVE-2022-32784
      https://nvd.nist.gov/vuln/detail/CVE-2022-32784
[ 20 ] CVE-2022-32792
      https://nvd.nist.gov/vuln/detail/CVE-2022-32792
[ 21 ] CVE-2022-32893
      https://nvd.nist.gov/vuln/detail/CVE-2022-32893
[ 22 ] WSA-2022-0002
      https://webkitgtk.org/security/WSA-2022-0002.html
[ 23 ] WSA-2022-0003
      https://webkitgtk.org/security/WSA-2022-0003.html
[ 24 ] WSA-2022-0007
      https://webkitgtk.org/security/WSA-2022-0007.html
[ 25 ] WSA-2022-0008
      https://webkitgtk.org/security/WSA-2022-0008.html

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202208-39

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmMP9NIACgkQFMQkOaVy
+9mVExAAq7pA0IGJBFPx8y1JmOb1SZm0KW7fKzhXMbdpigv2FkTSPT5LmWgwi5ld
jRNiuk2jRZUspJ5JJ2YppL+8m0x5SIE41TvPj9wLEL/cRbLFeIF+I9r2nTlRUv3r
4NDIbta5ykt9Nq9FJZKo+IAxmiwnWa4VTrqdN363ppzEQVtMcdM4U8yAEWiwcX/W
3R0wEjHlqbDC+ARwoAVCqOfhMoip68U23AO3Obr00gPKxhkh+D9jq9F+aJytrzgh
ldJf2Tk29Rzy/zeUNF8QndjQJPw/J8j8zTLvqRSg+1OWyorrmv2AAFqlMcrUmnwh
YpKaTIDbZyZ1vkOlFvPJgxEMuTxCAzxr0vQMiwbxh+Nv/174qtdPI4lbUY4HDJY5
WhsgCcFVSCMS2zNgjD3zLmPW/xGkGRV3vLKOvKc6tMFaKjftHa26Sj0ZxmOula8w
ery4CytXnRQWE7qYb0BPmC6TVaJ+hp9LwpMIhvTAjPRm2x8U8rdrerQmjV5rjOt1
+Rdy0jnK81I9l1DRYijGHzG0oXvgeqIpcVNHPyk6hFR0fRO9psroyf7tAj8zEIlx
dCJJFoptmXNeKns689NSyegWrICo2a1eU3ze3GaFC/FmSe5Hu0T6dlPG5qUn7tK7
zlKfoUnjt+lHiSxG+q6hSbf2FwfLSKU8AwPJnIqJA2gJKOm50M4=
=nMkn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.