Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5695-1] webkit2gtk security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5695-1] webkit2gtk security update


Chronologisch Thread  
  • From: Alberto Garcia <berto AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5695-1] webkit2gtk security update
  • Date: Wed, 22 May 2024 08:56:56 +0000
  • List-archive: https://lists.debian.org/msgid-search/Zk2zWMDGkJkShl4l AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=SzRjklCN2ZObfv5DUuWYZb/xcySu5947quRt9Mi06VQ=; b=Qd JjN4wPp/ZZWnnAIaErZV3h136jrG8k8A2Q+v6HWgHZobInH+qvSVZAWP0EWzwZluxx6dRhdv4QYdk c+qcTvvWH7a2HtwlBxpl62/Ud0em2MtywUMzGSgLHlGRFGFsMlGRSY6Qr4ZsOsveYCWEJGY+hNQLs TYT5zb5kzwaHcEZnkEokLQor+Br55EYQ6VhEKzilmzHCk4aCxWgIFQJRA3PBFG7kwJe3hF3Ao3OcK zIp1IwGWomiH6E9Cp+mrdoyg25xcP5Rhoam8oljMTFL2HZZpFU7YPBwYqH/4oFiWgqiEoHBTetuPh xXh+k0Vd4H3hE7l0a5u22WVBpV+miNQw==;
  • Old-return-path: <berto AT debian.org>
  • Priority: urgent
  • Resent-date: Wed, 22 May 2024 09:15:11 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <l-9muWVHZ-.A.XP5H.eebTmB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5695-1 security AT debian.org
https://www.debian.org/security/ Alberto Garcia
May 22, 2024 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : webkit2gtk
CVE ID : CVE-2024-27834

The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-27834

Manfred Paul discovered that an attacker with arbitrary read and
write capability may be able to bypass Pointer Authentication.

For the oldstable distribution (bullseye), this problem has been fixed
in version 2.44.2-1~deb11u1.

For the stable distribution (bookworm), this problem has been fixed in
version 2.44.2-1~deb12u1.

We recommend that you upgrade your webkit2gtk packages.

For the detailed security status of webkit2gtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/webkit2gtk

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmZNsSQACgkQAAyEYu0C
2AL2wxAAnx+ORCkML2MQZukV0lBt7yHzBHWaZHDWF8C3hbo8DPxqpNPGSRwpLb6M
xzRbW+7LvdlQUuSEMs0ms00jh1wkmQh1cAa09n778+pYhu5oLm09HOU51ybWaWRM
gojJiHC6svqhov5vxtqbSTUrpXzGQhp9ZYUAyCI49eJSzROIdk188CHHY1PxHZH1
nwlQddTeaL63f+0nyXzHomFtgOhyA6ESmVgunS8/yoIxQUOn3T6MQOvdKlizMJAr
watZ4fQq69AEqFMC2x8cCIZ6zZAhu4dLwagnundEdwZxeKRa6vAv6N5BLFx9lC8q
HARmaMttDl1+3AMHwMiZDqdNt++L4Ldgy26PJQa8hsDlAmXQsR5qtR/xmS7+l6AN
euXWeyF2DBM3GZgRzsACFJsnqYkQ9snQZdSYzHi2//xyskTpyHxYwMp/wFp4Kirt
F05d66TocWkWviuYddytl0cRGb3X1I7pB+8vkw90ugIMJKFxh6cXDDPch6kTdMLg
YPsSxV8/h1jcxr5MgST1LntvvhgGT70YV9HWJleQ33bmWqEQ6xF7vrIsKy3MiFx1
jKGoI7GvgOrWRDUIZuw4680f9Hv4Cpz4R0uKMOS4wTbrEQkhv96E/sAcER8P9VYm
9U6AuFAoA5KRU8BysUD3A/PzHo+wKwTSBUuKUGex8HnPIfmUEyw=
=yLoR
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5695-1] webkit2gtk security update, Alberto Garcia, 22.05.2024

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang