This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============3016997134887621106== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="gFJ94r1VEdXSwhVvjUkGFcDbmTM6nD5xC"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --gFJ94r1VEdXSwhVvjUkGFcDbmTM6nD5xC Content-Type: multipart/mixed; boundary="0AMHQ1hcN4vGu65lbewoSvtk3UaTHfUFq" From: Marc Deslauriers <marc.deslauriers@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <47f2d1af-f106-546b-58f9-abce389f8c98@canonical.com> Subject: [USN-3257-1] WebKitGTK+ vulnerabilities
--0AMHQ1hcN4vGu65lbewoSvtk3UaTHfUFq Content-Type: text/plain; charset=utf- Content-Transfer-Encoding: quoted-printable
========================================================================== Ubuntu Security Notice USN-3257-1 April 10, 2017
webkit2gtk vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.10 - Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in WebKitGTK+.
Software Description: - webkit2gtk: Web content engine library for GTK+
Details:
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.10: libjavascriptcoregtk-4.0-18 2.16.1-0ubuntu0.16.10.1 libwebkit2gtk-4.0-37 2.16.1-0ubuntu0.16.10.1
Ubuntu 16.04 LTS: libjavascriptcoregtk-4.0-18 2.16.1-0ubuntu0.16.04.1 libwebkit2gtk-4.0-37 2.16.1-0ubuntu0.16.04.1
This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK+, such as Epiphany, to make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-3257-1 CVE-2016-9642, CVE-2016-9643, CVE-2017-2364, CVE-2017-2367, CVE-2017-2376, CVE-2017-2377, CVE-2017-2386, CVE-2017-2392, CVE-2017-2394, CVE-2017-2395, CVE-2017-2396, CVE-2017-2405, CVE-2017-2415, CVE-2017-2419, CVE-2017-2433, CVE-2017-2442, CVE-2017-2445, CVE-2017-2446, CVE-2017-2447, CVE-2017-2454, CVE-2017-2455, CVE-2017-2457, CVE-2017-2459, CVE-2017-2460, CVE-2017-2464, CVE-2017-2465, CVE-2017-2466, CVE-2017-2468, CVE-2017-2469, CVE-2017-2470, CVE-2017-2471, CVE-2017-2475, CVE-2017-2476, CVE-2017-2481
Package Information: https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.1-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.1-0ubuntu0.16.04.1
--0AMHQ1hcN4vGu65lbewoSvtk3UaTHfUFq--
--gFJ94r1VEdXSwhVvjUkGFcDbmTM6nD5xC Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2
iQIcBAEBCgAGBQJY68YfAAoJEGVp2FWnRL6Tcf4QAJYlRzSBOGGgNSpGQHwsKXp1 u4oDQ86eBJgZF5pWODibnHIdcn5FzRhuelIAuN9XHxSOVXn1M9+u1o/7fq68mJ4R 7HTolC/7T8B4kRL9J5t/Tnouu7dDjkybtIozaAENICfkqIgTCG1PMlzhi08AkFGW iEFozT7pz9tF4I3TR2a5B3k8+IcjWLwYnmEZ4LbfsJym+VL/wDWN3YukNfB91M74 840YsJof6UOaMffVXiNMYlQaj39yAgXXQYjwI/0++CVEui/P5N9Mh9NrYmAZ3WT6 TL8o5fEvD1GwmGJ7pEhPM2d42qtkoZAHE8c2sHqAoP4Kr/iKVlrKK3/yESIXnS9b rPEtvbZL9KO7AwMzmR5FS7/SZ2NQ+przg1Rlz6QNf58HxbWE/cRh0pzz7A2PVjEm D1/JvKhBH9Om5AfeCKnKPLBhfvi5WaiqjUNK7FntK+LgUEAJAlEejOI0bvpKvrIe eGDVOYb9Z9g6iNUhkBy3BFigRS/zk13dFyhTtdTyK8a9AMms22cFSufKv51Bo1I6 Go8OI1TF2PlGqv32Zp/VAsQjXgeWFGKNswAcKRMaUiq/yqrEIaKVkt8gcpYWtOhQ ZJNITvQtx7zEiy7pK9qKl87Gn+nM86XM4sc7z8gPA00OeHDFDLyX8awOyLXvK22g h+beiCvHsQjNxzyIBLhr =XbIO -----END PGP SIGNATURE-----
--gFJ94r1VEdXSwhVvjUkGFcDbmTM6nD5xC--
--===============3016997134887621106== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============3016997134887621106==--
|