[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:1677-1 -- SLES webkit2gtk3, libjavascriptcoregtk, libwebkit2gtk-4_0-37, typelib-1_0-JavaScriptCore-4_0, typelib-1_0-WebKit2-4_0, typelib-1_0-WebKit2WebExtension-4_0, webkit2gtk-4_0-injected-bundles, libwebkit2gtk3-lang

ID: oval:org.secpod.oval:def:89046309Date: (C)2022-05-25   (M)2023-12-05
Class: PATCHFamily: unix




This update for webkit2gtk3 fixes the following issues: Update to version 2.36.0 : - CVE-2022-22624: Fixed use after free that may lead to arbitrary code execution. - CVE-2022-22628: Fixed use after free that may lead to arbitrary code execution. - CVE-2022-22629: Fixed a buffer overflow that may lead to arbitrary code execution. - CVE-2022-22637: Fixed an unexpected cross-origin behavior due to a logic error. Missing CVE reference for the update to 2.34.6 : - CVE-2022-22594: Fixed a cross-origin issue in the IndexDB API.

Platform:
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP4
Product:
webkit2gtk3
libjavascriptcoregtk
libwebkit2gtk-4_0-37
typelib-1_0-JavaScriptCore-4_0
typelib-1_0-WebKit2-4_0
typelib-1_0-WebKit2WebExtension-4_0
webkit2gtk-4_0-injected-bundles
libwebkit2gtk3-lang
Reference:
SUSE-SU-2022:1677-1
CVE-2022-22594
CVE-2022-22624
CVE-2022-22628
CVE-2022-22629
CVE-2022-22637
CVE    5
CVE-2022-22624
CVE-2022-22628
CVE-2022-22629
CVE-2022-22637
...

© SecPod Technologies