SUSE-SU-2019:0497-1

Source
https://www.suse.com/support/update/announcement/2019/suse-su-20190497-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:0497-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2019:0497-1
Related
Published
2019-02-26T15:43:40Z
Modified
2019-02-26T15:43:40Z
Summary
Security update for webkit2gtk3
Details

This update for webkit2gtk3 to version 2.22.6 fixes the following issues (boo#1124937 boo#1119558):

Security vulnerabilities fixed:

  • CVE-2018-4437: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling. (boo#1119553)
  • CVE-2018-4438: Processing maliciously crafted web content may lead to arbitrary code execution. A logic issue existed resulting in memory corruption. This was addressed with improved state management. (boo#1119554)
  • CVE-2018-4441: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling. (boo#1119555)
  • CVE-2018-4442: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling. (boo#1119556)
  • CVE-2018-4443: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling. (boo#1119557)
  • CVE-2018-4464: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling. (boo#1119558)
  • CVE-2019-6212: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
  • CVE-2019-6215: Processing maliciously crafted web content may lead to arbitrary code execution. A type confusion issue was addressed with improved memory handling.
  • CVE-2019-6216: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
  • CVE-2019-6217: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
  • CVE-2019-6226: Processing maliciously crafted web content may lead to arbitrary code execution. Multiple memory corruption issues were addressed with improved memory handling.
  • CVE-2019-6227: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling.
  • CVE-2019-6229: Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue was addressed with improved validation.
  • CVE-2019-6233: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling.
  • CVE-2019-6234: Processing maliciously crafted web content may lead to arbitrary code execution. A memory corruption issue was addressed with improved memory handling.

Other bug fixes and changes:

  • Make kinetic scrolling slow down smoothly when reaching the ends of pages, instead of abruptly, to better match the GTK+ behaviour.
  • Fix Web inspector magnifier under Wayland.
  • Fix garbled rendering of some websites (e.g. YouTube) while scrolling under X11.
  • Fix several crashes, race conditions, and rendering issues.

For a detailed list of changes, please refer to:

  • https://webkitgtk.org/security/WSA-2019-0001.html
  • https://webkitgtk.org/2019/02/09/webkitgtk2.22.6-released.html
  • https://webkitgtk.org/security/WSA-2018-0009.html
  • https://webkitgtk.org/2018/12/13/webkitgtk2.22.5-released.html
References

Affected packages

SUSE:Linux Enterprise Module for Basesystem 15 / webkit2gtk3

Package

Name
webkit2gtk3
Purl
purl:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.22.6-3.18.2

Ecosystem specific

{
    "binaries": [
        {
            "libwebkit2gtk-4_0-37": "2.22.6-3.18.2",
            "libwebkit2gtk3-lang": "2.22.6-3.18.2",
            "libjavascriptcoregtk-4_0-18": "2.22.6-3.18.2",
            "webkit2gtk-4_0-injected-bundles": "2.22.6-3.18.2"
        }
    ]
}

SUSE:Linux Enterprise Module for Desktop Applications 15 / webkit2gtk3

Package

Name
webkit2gtk3
Purl
purl:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.22.6-3.18.2

Ecosystem specific

{
    "binaries": [
        {
            "typelib-1_0-WebKit2-4_0": "2.22.6-3.18.2",
            "typelib-1_0-JavaScriptCore-4_0": "2.22.6-3.18.2",
            "typelib-1_0-WebKit2WebExtension-4_0": "2.22.6-3.18.2",
            "webkit2gtk3-devel": "2.22.6-3.18.2"
        }
    ]
}