Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in WebkitGTK+
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in WebkitGTK+
ID: 201909-05
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: Fr, 6. September 2019, 19:11
Referenzen: https://nvd.nist.gov/vuln/detail/CVE-2019-8677
https://nvd.nist.gov/vuln/detail/CVE-2019-8503
https://nvd.nist.gov/vuln/detail/CVE-2019-8683
https://nvd.nist.gov/vuln/detail/CVE-2019-8680
https://nvd.nist.gov/vuln/detail/CVE-2019-8595
https://nvd.nist.gov/vuln/detail/CVE-2019-8666
https://nvd.nist.gov/vuln/detail/CVE-2019-8686
https://nvd.nist.gov/vuln/detail/CVE-2019-8681
https://nvd.nist.gov/vuln/detail/CVE-2019-8535
https://nvd.nist.gov/vuln/detail/CVE-2019-8671
https://nvd.nist.gov/vuln/detail/CVE-2019-8536
https://nvd.nist.gov/vuln/detail/CVE-2019-8669
https://nvd.nist.gov/vuln/detail/CVE-2019-6251
https://nvd.nist.gov/vuln/detail/CVE-2019-8689
https://nvd.nist.gov/vuln/detail/CVE-2019-8559
https://nvd.nist.gov/vuln/detail/CVE-2019-8518
https://nvd.nist.gov/vuln/detail/CVE-2019-8684
https://nvd.nist.gov/vuln/detail/CVE-2019-8551
https://nvd.nist.gov/vuln/detail/CVE-2019-8523
https://nvd.nist.gov/vuln/detail/CVE-2019-8558
https://nvd.nist.gov/vuln/detail/CVE-2019-8607
https://nvd.nist.gov/vuln/detail/CVE-2019-8678
https://nvd.nist.gov/vuln/detail/CVE-2019-8506
https://nvd.nist.gov/vuln/detail/CVE-2019-8563
https://webkitgtk.org/security/WSA-2019-0004.html
https://nvd.nist.gov/vuln/detail/CVE-2019-8515
https://nvd.nist.gov/vuln/detail/CVE-2019-8644
https://nvd.nist.gov/vuln/detail/CVE-2019-7292
https://webkitgtk.org/security/WSA-2019-0002.html
https://nvd.nist.gov/vuln/detail/CVE-2019-8524
https://nvd.nist.gov/vuln/detail/CVE-2019-6201
https://nvd.nist.gov/vuln/detail/CVE-2019-8687
https://nvd.nist.gov/vuln/detail/CVE-2019-8679
https://nvd.nist.gov/vuln/detail/CVE-2019-8688
https://nvd.nist.gov/vuln/detail/CVE-2019-11070
https://nvd.nist.gov/vuln/detail/CVE-2019-7285
https://nvd.nist.gov/vuln/detail/CVE-2019-8672
https://nvd.nist.gov/vuln/detail/CVE-2019-8649
https://nvd.nist.gov/vuln/detail/CVE-2019-8615
https://nvd.nist.gov/vuln/detail/CVE-2019-8658
https://nvd.nist.gov/vuln/detail/CVE-2019-8544
https://nvd.nist.gov/vuln/detail/CVE-2019-8676
https://nvd.nist.gov/vuln/detail/CVE-2019-8690
https://nvd.nist.gov/vuln/detail/CVE-2019-8673
Applikationen: WebkitGTK+

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--oXVE5VKMueliqU9FhFOC6ReDvW1jmQnK8
Content-Type: multipart/mixed;
boundary="IEgXniTY1IC9hxvJnQVWKEJKqgq7uP7c7";
protected-headers="v1"
From: Thomas Deutschmann <whissi@gentoo.org>
Reply-To: security@gentoo.org
To: gentoo-announce@lists.gentoo.org
Message-ID: <b77d7aba-9bed-775a-55a7-3d53e4d7e2ea@gentoo.org>
Subject: [ GLSA 201909-05 ] WebkitGTK+: Multiple vulnerabilities

--IEgXniTY1IC9hxvJnQVWKEJKqgq7uP7c7
Content-Type: text/plain; charset=utf-8
Content-Language: en-U
Content-Transfer-Encoding: quoted-printable

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 201909-05
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Normal
Title: WebkitGTK+: Multiple vulnerabilities
Date: September 06, 2019
Bugs: #683234, #686216, #693122
ID: 201909-05

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in WebkitGTK+, the worst of
which could result in the arbitrary execution of code.

Background
==========

WebKitGTK+ is a full-featured port of the WebKit rendering engine,
suitable for projects requiring any kind of web integration, from
hybrid HTML/CSS applications to full-fledged web browsers.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-libs/webkit-gtk < 2.24.4 >= 2.24.4

Description
===========

Multiple vulnerabilities have been discovered in WebkitGTK+. Please
review the CVE identifiers referenced below for details.

Impact
======

An attacker, by enticing a user to visit maliciously crafted web
content, may be able to execute arbitrary code or cause memory
corruption.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All WebkitGTK+ users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.24.4"

References
==========

[ 1 ] CVE-2019-11070
https://nvd.nist.gov/vuln/detail/CVE-2019-11070
[ 2 ] CVE-2019-6201
https://nvd.nist.gov/vuln/detail/CVE-2019-6201
[ 3 ] CVE-2019-6251
https://nvd.nist.gov/vuln/detail/CVE-2019-6251
[ 4 ] CVE-2019-7285
https://nvd.nist.gov/vuln/detail/CVE-2019-7285
[ 5 ] CVE-2019-7292
https://nvd.nist.gov/vuln/detail/CVE-2019-7292
[ 6 ] CVE-2019-8503
https://nvd.nist.gov/vuln/detail/CVE-2019-8503
[ 7 ] CVE-2019-8506
https://nvd.nist.gov/vuln/detail/CVE-2019-8506
[ 8 ] CVE-2019-8515
https://nvd.nist.gov/vuln/detail/CVE-2019-8515
[ 9 ] CVE-2019-8518
https://nvd.nist.gov/vuln/detail/CVE-2019-8518
[ 10 ] CVE-2019-8523
https://nvd.nist.gov/vuln/detail/CVE-2019-8523
[ 11 ] CVE-2019-8524
https://nvd.nist.gov/vuln/detail/CVE-2019-8524
[ 12 ] CVE-2019-8535
https://nvd.nist.gov/vuln/detail/CVE-2019-8535
[ 13 ] CVE-2019-8536
https://nvd.nist.gov/vuln/detail/CVE-2019-8536
[ 14 ] CVE-2019-8544
https://nvd.nist.gov/vuln/detail/CVE-2019-8544
[ 15 ] CVE-2019-8551
https://nvd.nist.gov/vuln/detail/CVE-2019-8551
[ 16 ] CVE-2019-8558
https://nvd.nist.gov/vuln/detail/CVE-2019-8558
[ 17 ] CVE-2019-8559
https://nvd.nist.gov/vuln/detail/CVE-2019-8559
[ 18 ] CVE-2019-8563
https://nvd.nist.gov/vuln/detail/CVE-2019-8563
[ 19 ] CVE-2019-8595
https://nvd.nist.gov/vuln/detail/CVE-2019-8595
[ 20 ] CVE-2019-8607
https://nvd.nist.gov/vuln/detail/CVE-2019-8607
[ 21 ] CVE-2019-8615
https://nvd.nist.gov/vuln/detail/CVE-2019-8615
[ 22 ] CVE-2019-8644
https://nvd.nist.gov/vuln/detail/CVE-2019-8644
[ 23 ] CVE-2019-8644
https://nvd.nist.gov/vuln/detail/CVE-2019-8644
[ 24 ] CVE-2019-8649
https://nvd.nist.gov/vuln/detail/CVE-2019-8649
[ 25 ] CVE-2019-8649
https://nvd.nist.gov/vuln/detail/CVE-2019-8649
[ 26 ] CVE-2019-8658
https://nvd.nist.gov/vuln/detail/CVE-2019-8658
[ 27 ] CVE-2019-8658
https://nvd.nist.gov/vuln/detail/CVE-2019-8658
[ 28 ] CVE-2019-8666
https://nvd.nist.gov/vuln/detail/CVE-2019-8666
[ 29 ] CVE-2019-8666
https://nvd.nist.gov/vuln/detail/CVE-2019-8666
[ 30 ] CVE-2019-8669
https://nvd.nist.gov/vuln/detail/CVE-2019-8669
[ 31 ] CVE-2019-8669
https://nvd.nist.gov/vuln/detail/CVE-2019-8669
[ 32 ] CVE-2019-8671
https://nvd.nist.gov/vuln/detail/CVE-2019-8671
[ 33 ] CVE-2019-8671
https://nvd.nist.gov/vuln/detail/CVE-2019-8671
[ 34 ] CVE-2019-8672
https://nvd.nist.gov/vuln/detail/CVE-2019-8672
[ 35 ] CVE-2019-8672
https://nvd.nist.gov/vuln/detail/CVE-2019-8672
[ 36 ] CVE-2019-8673
https://nvd.nist.gov/vuln/detail/CVE-2019-8673
[ 37 ] CVE-2019-8673
https://nvd.nist.gov/vuln/detail/CVE-2019-8673
[ 38 ] CVE-2019-8676
https://nvd.nist.gov/vuln/detail/CVE-2019-8676
[ 39 ] CVE-2019-8676
https://nvd.nist.gov/vuln/detail/CVE-2019-8676
[ 40 ] CVE-2019-8677
https://nvd.nist.gov/vuln/detail/CVE-2019-8677
[ 41 ] CVE-2019-8677
https://nvd.nist.gov/vuln/detail/CVE-2019-8677
[ 42 ] CVE-2019-8678
https://nvd.nist.gov/vuln/detail/CVE-2019-8678
[ 43 ] CVE-2019-8678
https://nvd.nist.gov/vuln/detail/CVE-2019-8678
[ 44 ] CVE-2019-8679
https://nvd.nist.gov/vuln/detail/CVE-2019-8679
[ 45 ] CVE-2019-8679
https://nvd.nist.gov/vuln/detail/CVE-2019-8679
[ 46 ] CVE-2019-8680
https://nvd.nist.gov/vuln/detail/CVE-2019-8680
[ 47 ] CVE-2019-8680
https://nvd.nist.gov/vuln/detail/CVE-2019-8680
[ 48 ] CVE-2019-8681
https://nvd.nist.gov/vuln/detail/CVE-2019-8681
[ 49 ] CVE-2019-8681
https://nvd.nist.gov/vuln/detail/CVE-2019-8681
[ 50 ] CVE-2019-8683
https://nvd.nist.gov/vuln/detail/CVE-2019-8683
[ 51 ] CVE-2019-8683
https://nvd.nist.gov/vuln/detail/CVE-2019-8683
[ 52 ] CVE-2019-8684
https://nvd.nist.gov/vuln/detail/CVE-2019-8684
[ 53 ] CVE-2019-8684
https://nvd.nist.gov/vuln/detail/CVE-2019-8684
[ 54 ] CVE-2019-8686
https://nvd.nist.gov/vuln/detail/CVE-2019-8686
[ 55 ] CVE-2019-8686
https://nvd.nist.gov/vuln/detail/CVE-2019-8686
[ 56 ] CVE-2019-8687
https://nvd.nist.gov/vuln/detail/CVE-2019-8687
[ 57 ] CVE-2019-8687
https://nvd.nist.gov/vuln/detail/CVE-2019-8687
[ 58 ] CVE-2019-8688
https://nvd.nist.gov/vuln/detail/CVE-2019-8688
[ 59 ] CVE-2019-8688
https://nvd.nist.gov/vuln/detail/CVE-2019-8688
[ 60 ] CVE-2019-8689
https://nvd.nist.gov/vuln/detail/CVE-2019-8689
[ 61 ] CVE-2019-8689
https://nvd.nist.gov/vuln/detail/CVE-2019-8689
[ 62 ] CVE-2019-8690
https://nvd.nist.gov/vuln/detail/CVE-2019-8690
[ 63 ] CVE-2019-8690
https://nvd.nist.gov/vuln/detail/CVE-2019-8690
[ 64 ] WSA-2019-0002
https://webkitgtk.org/security/WSA-2019-0002.html
[ 65 ] WSA-2019-0004
https://webkitgtk.org/security/WSA-2019-0004.html

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/201909-05

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2019 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5


--IEgXniTY1IC9hxvJnQVWKEJKqgq7uP7c7--

--oXVE5VKMueliqU9FhFOC6ReDvW1jmQnK8
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQGTBAEBCgB9FiEEExKRzo+LDXJgXHuURObr3Jv2BVkFAl1yhVZfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDEz
MTI5MUNFOEY4QjBENzI2MDVDN0I5NDQ0RTZFQkRDOUJGNjA1NTkACgkQRObr3Jv2
BVnIVwf/eQ25/O5TdRdygGzocm2HGgdLby5oXp0RKBMp+xeMfR3jLUQmElGJe4xl
mOecyM1p1aWm2CVUdtXZcc+MlgsRwQnQgwHuGEUChCLD5lfMFkU6DdEdp7Nt+FKP
oQO2QGkeraTOfBNk+ytGR5tvIiM4ATwmRQXt5WugkvgxzetkT3W+LwgWL9TJJu/L
WhWMiG4dJ4m16a7BcjsWHvDvBdgadxn9nwoHthLH6+PnuPVyBEc7gwz8r2PppR4q
FRvnm4tVHhJ1HBmtDEhltdiSg8DoI5r6qik/a3ZiNznUrWB1W+V6q+ctSNsNLgqt
UiOtIaVDkR8wtFKqST+6GdN3Zt4uTA==
=SJGx
-----END PGP SIGNATURE-----

--oXVE5VKMueliqU9FhFOC6ReDvW1jmQnK8--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung