Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5397-1] wpewebkit security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5397-1] wpewebkit security update


Chronologisch Thread  
  • From: Alberto Garcia <berto AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5397-1] wpewebkit security update
  • Date: Wed, 3 May 2023 09:38:25 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/ZFIrkQY85OhsAQ1y AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=jT5Mfnc+24yMiVFOE3xmHX6yGY0ViEu/6L4ZnL/KmNE=; b=tI a3nPUvN/K/P1RNcMw7PfD+igk+HhhTRXaW6yL0gKDcfa4UJLmDblud0uBNSV7JZxyR3QO7046fbcB 5D2TRDKrhjfIffC6Q9n0nxIg1lFzGIuDawzqPzflZf2cq+P1C3USuae2vKZ2Lb+NMcB8vzOfA0t7p y4qR9oDKTI8ZE2VQWJkJLANV5D/5mQngkiO1O4AA5xNg/unrgyrgRmgfA0dA6IHZv00esiScYDloX au9LrsakK5bmManZ1azOlf9cty2EYT70V+rDWo9hrsRMyE1u1Q16DFNG2Vn4NiLLvmx1Q3ZDf/I91 rEURua6BIyzqQ8uDqpTeJmexw9qvU7Lg==;
  • Old-return-path: <berto AT debian.org>
  • Priority: urgent
  • Resent-date: Wed, 3 May 2023 09:54:14 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <uH17YMbGc9O.A.R8E.G9iUkB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5397-1 security AT debian.org
https://www.debian.org/security/ Alberto Garcia
May 03, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : wpewebkit
CVE ID : CVE-2022-0108 CVE-2022-32885 CVE-2023-27932 CVE-2023-27954
CVE-2023-28205

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2022-0108

Luan Herrera discovered that an HTML document may be able to
render iframes with sensitive user information.

CVE-2022-32885

P1umer and Q1IQ discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2023-27932

An anonymous researcher discovered that processing maliciously
crafted web content may bypass Same Origin Policy.

CVE-2023-27954

An anonymous researcher discovered that a website may be able to
track sensitive user information.

CVE-2023-28205

Clement Lecigne and Donncha O Cearbhaill discovered that
processing maliciously crafted web content may lead to arbitrary
code execution. Apple is aware of a report that this issue may
have been actively exploited.

For the stable distribution (bullseye), these problems have been fixed in
version 2.38.6-1~deb11u1.

We recommend that you upgrade your wpewebkit packages.

For the detailed security status of wpewebkit please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/wpewebkit

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmRSI8AACgkQAAyEYu0C
2AIt9A/+MrTb+Oah+n+lUC3vRyDCvuXqHCxmtmCNKPqBSghIYFyfszRk4IsQd43s
1iEHpShpn6mj2gKn7yZ/Qpyd7KKkMBHp2HFiAYlNRH6c7oD5kVY9IvW1Rb3kqcm2
fYT/kvBxCSCEkhQiLIhG4ojr36eq9GwRtGZh/OnlCx9ds0WXwukC8Y1EdhsFi0N3
v/SiEw6eciN320RvEVpvNV35ecz2DvptZYl9RcIa0CPK+az4cNgceXT78oQq5Kzi
0bkIfXoaxrxVeqvqpYxPEqX7iXoLkJCRY3em1QU9VQmoTt5N93PMduBnMQOXHnjP
MB48I6lBY2iqOvfDAdi7zbwfkcCNL7EpOy6tKMw3s0E65Fwe4bedBG/EcDsYNdih
mOcdEuoNigrXPA705x2+Aqtg/2MzB03FOVGP9SkYesJOV8hNSDW02oJ/KYxf3yw7
IufammTBTTRZ/k+udpAUA4PQI1SH6Luj+jL5Rtr2BykDZ9KfnrpCqE4wlsqsuVeP
mMFLQL4E025D0dWVxpL+tapa7e9G+SggFRv1P+F+RaP2FGcsuE0QoRLEuBV0ARds
AiQlzMibbErRJtVYAJwSPZW0I2RutA5WkJI7wQAtSWWbTbVOODe2djR84yFe42X9
Xuj7ZeffUlgril/G+goFZh/CBMXWkwzf0iw7CXF8BP5i11FKekU=
=Od4H
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5397-1] wpewebkit security update, Alberto Garcia, 03.05.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang