WebkitGTK+: Multiple vulnerabilities Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in the arbitrary execution of code. webkit-gtk 2021-04-30 2021-04-30 770793 773193 local, remote 2.30.6 2.30.6

WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers.

Multiple vulnerabilities have been discovered in WebkitGTK+. Please review the CVE identifiers referenced below for details.

An attacker, by enticing a user to visit maliciously crafted web content, may be able to execute arbitrary code, violate iframe sandboxing policy, access restricted ports on arbitrary servers, cause memory corruption, or could cause a Denial of Service condition.

There is no known workaround at this time.

All WebkitGTK+ users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.30.6"
CVE-2020-13558 CVE-2020-27918 CVE-2020-29623 CVE-2020-9947 CVE-2021-1765 CVE-2021-1789 CVE-2021-1799 CVE-2021-1801 CVE-2021-1870 WSA-2021-0001 WSA-2021-0002 whissi whissi