From 623ee73d661e5ed8475cb264511f683407d87365 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Sun, 12 Apr 2020 03:41:30 +0100 Subject: gentoo Easter resync : 12.04.2020 --- metadata/glsa/glsa-202003-22.xml | 94 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 94 insertions(+) create mode 100644 metadata/glsa/glsa-202003-22.xml (limited to 'metadata/glsa/glsa-202003-22.xml') diff --git a/metadata/glsa/glsa-202003-22.xml b/metadata/glsa/glsa-202003-22.xml new file mode 100644 index 000000000000..c69d16f0a64e --- /dev/null +++ b/metadata/glsa/glsa-202003-22.xml @@ -0,0 +1,94 @@ + + + + WebkitGTK+: Multiple vulnerabilities + Multiple vulnerabilities have been found in WebKitGTK+, the worst + of which may lead to arbitrary code execution. + + webkitgtk+ + 2020-03-15 + 2020-03-15 + 699156 + 706374 + 709612 + remote + + + 2.26.4 + 2.26.4 + + + +

WebKitGTK+ is a full-featured port of the WebKit rendering engine, + suitable for projects requiring any kind of web integration, from hybrid + HTML/CSS applications to full-fledged web browsers. +

+
+ +

Multiple vulnerabilities have been discovered in WebKitGTK+. Please + review the referenced CVE identifiers for details. +

+
+ +

A remote attacker could execute arbitrary code, cause a Denial of + Service condition, bypass intended memory-read restrictions, conduct a + timing side-channel attack to bypass the Same Origin Policy or obtain + sensitive information. +

+
+ +

There is no known workaround at this time.

+
+ +

All WebkitGTK+ users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.26.4" + + +
+ + CVE-2019-8625 + CVE-2019-8674 + CVE-2019-8707 + CVE-2019-8710 + CVE-2019-8719 + CVE-2019-8720 + CVE-2019-8726 + CVE-2019-8733 + CVE-2019-8735 + CVE-2019-8743 + CVE-2019-8763 + CVE-2019-8764 + CVE-2019-8765 + CVE-2019-8766 + CVE-2019-8768 + CVE-2019-8769 + CVE-2019-8771 + CVE-2019-8782 + CVE-2019-8783 + CVE-2019-8808 + CVE-2019-8811 + CVE-2019-8812 + CVE-2019-8813 + CVE-2019-8814 + CVE-2019-8815 + CVE-2019-8816 + CVE-2019-8819 + CVE-2019-8820 + CVE-2019-8821 + CVE-2019-8822 + CVE-2019-8823 + CVE-2019-8835 + CVE-2019-8844 + CVE-2019-8846 + CVE-2020-3862 + CVE-2020-3864 + CVE-2020-3865 + CVE-2020-3867 + CVE-2020-3868 + + whissi + whissi +
-- cgit v1.2.3