MGASA-2023-0177

Source
https://advisories.mageia.org/MGASA-2023-0177.html
Import Source
https://advisories.mageia.org/MGASA-2023-0177.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0177
Related
Published
2023-05-21T08:42:44Z
Modified
2023-05-21T07:19:59Z
Summary
Updated webkit2 packages fix security vulnerability
Details

HTML document may be able to render iframes with sensitive user information (CVE-2022-0108) maliciously crafted web content may lead to arbitrary code execution. (CVE-2022-32885) use-after-free vulnerability exists in WebCore::RenderLayer. This issue allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. (CVE-2023-25358) maliciously crafted web content may bypass Same Origin Policy (CVE-2023-27932) Website may be able to track sensitive user information. Description: The issue was addressed by removing origin information. (CVE-2023-27954) maliciously crafted web content may lead to arbitrary code execution (CVE-2023-28205)

References
Credits

Affected packages

Mageia:8 / webkit2

Package

Name
webkit2
Purl
pkg:rpm/mageia/webkit2?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.38.6-1.mga8

Ecosystem specific

{
    "section": "core"
}