Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202208-39 ] WebKitGTK+: Multiple Vulnerabilities
Date: Wed, 31 Aug 2022 23:57:49
Message-Id: 166199009828.12.9496266521302596456@ec95405eafab
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202208-39
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: WebKitGTK+: Multiple Vulnerabilities
9 Date: August 31, 2022
10 Bugs: #866494, #864427, #856445, #861740, #837305, #845252, #839984, #833568, #832990
11 ID: 202208-39
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in WebkitGTK+, the worst of
19 which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 WebKitGTK+ is a full-featured port of the WebKit rendering engine,
25 suitable for projects requiring any kind of web integration, from hybrid
26 HTML/CSS applications to full-fledged web browsers.
27
28 Affected packages
29 =================
30
31 -------------------------------------------------------------------
32 Package / Vulnerable / Unaffected
33 -------------------------------------------------------------------
34 1 net-libs/webkit-gtk < 2.36.7 >= 2.36.7
35
36 Description
37 ===========
38
39 Multiple vulnerabilities have been discovered in WebKitGTK+. Please
40 review the CVE identifiers referenced below for details.
41
42 Impact
43 ======
44
45 Please review the referenced CVE identifiers for details.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All WebKitGTK+ users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.36.7"
59
60 References
61 ==========
62
63 [ 1 ] CVE-2022-2294
64 https://nvd.nist.gov/vuln/detail/CVE-2022-2294
65 [ 2 ] CVE-2022-22589
66 https://nvd.nist.gov/vuln/detail/CVE-2022-22589
67 [ 3 ] CVE-2022-22590
68 https://nvd.nist.gov/vuln/detail/CVE-2022-22590
69 [ 4 ] CVE-2022-22592
70 https://nvd.nist.gov/vuln/detail/CVE-2022-22592
71 [ 5 ] CVE-2022-22620
72 https://nvd.nist.gov/vuln/detail/CVE-2022-22620
73 [ 6 ] CVE-2022-22624
74 https://nvd.nist.gov/vuln/detail/CVE-2022-22624
75 [ 7 ] CVE-2022-22628
76 https://nvd.nist.gov/vuln/detail/CVE-2022-22628
77 [ 8 ] CVE-2022-22629
78 https://nvd.nist.gov/vuln/detail/CVE-2022-22629
79 [ 9 ] CVE-2022-22662
80 https://nvd.nist.gov/vuln/detail/CVE-2022-22662
81 [ 10 ] CVE-2022-22677
82 https://nvd.nist.gov/vuln/detail/CVE-2022-22677
83 [ 11 ] CVE-2022-26700
84 https://nvd.nist.gov/vuln/detail/CVE-2022-26700
85 [ 12 ] CVE-2022-26709
86 https://nvd.nist.gov/vuln/detail/CVE-2022-26709
87 [ 13 ] CVE-2022-26710
88 https://nvd.nist.gov/vuln/detail/CVE-2022-26710
89 [ 14 ] CVE-2022-26716
90 https://nvd.nist.gov/vuln/detail/CVE-2022-26716
91 [ 15 ] CVE-2022-26717
92 https://nvd.nist.gov/vuln/detail/CVE-2022-26717
93 [ 16 ] CVE-2022-26719
94 https://nvd.nist.gov/vuln/detail/CVE-2022-26719
95 [ 17 ] CVE-2022-30293
96 https://nvd.nist.gov/vuln/detail/CVE-2022-30293
97 [ 18 ] CVE-2022-30294
98 https://nvd.nist.gov/vuln/detail/CVE-2022-30294
99 [ 19 ] CVE-2022-32784
100 https://nvd.nist.gov/vuln/detail/CVE-2022-32784
101 [ 20 ] CVE-2022-32792
102 https://nvd.nist.gov/vuln/detail/CVE-2022-32792
103 [ 21 ] CVE-2022-32893
104 https://nvd.nist.gov/vuln/detail/CVE-2022-32893
105 [ 22 ] WSA-2022-0002
106 https://webkitgtk.org/security/WSA-2022-0002.html
107 [ 23 ] WSA-2022-0003
108 https://webkitgtk.org/security/WSA-2022-0003.html
109 [ 24 ] WSA-2022-0007
110 https://webkitgtk.org/security/WSA-2022-0007.html
111 [ 25 ] WSA-2022-0008
112 https://webkitgtk.org/security/WSA-2022-0008.html
113
114 Availability
115 ============
116
117 This GLSA and any updates to it are available for viewing at
118 the Gentoo Security Website:
119
120 https://security.gentoo.org/glsa/202208-39
121
122 Concerns?
123 =========
124
125 Security is a primary focus of Gentoo Linux and ensuring the
126 confidentiality and security of our users' machines is of utmost
127 importance to us. Any security concerns should be addressed to
128 security@g.o or alternatively, you may file a bug at
129 https://bugs.gentoo.org.
130
131 License
132 =======
133
134 Copyright 2022 Gentoo Foundation, Inc; referenced text
135 belongs to its owner(s).
136
137 The contents of this document are licensed under the
138 Creative Commons - Attribution / Share Alike license.
139
140 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature