• [SECURITY] [DSA 4724-1] webkit2gtk security update

    From Moritz Muehlenhoff@1:229/2 to All on Wed Jul 15 22:40:02 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4724-1 [email protected] https://www.debian.org/security/ Alberto Garcia
    July 15, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : webkit2gtk
    CVE ID : CVE-2020-9802 CVE-2020-9803 CVE-2020-9805 CVE-2020-9806
    CVE-2020-9807 CVE-2020-9843 CVE-2020-9850 CVE-2020-13753

    The following vulnerabilities have been discovered in the webkit2gtk
    web engine:

    CVE-2020-9802

    Samuel Gross discovered that processing maliciously crafted web
    content may lead to arbitrary code execution.

    CVE-2020-9803

    Wen Xu discovered that processing maliciously crafted web content
    may lead to arbitrary code execution.

    CVE-2020-9805

    An anonymous researcher discovered that processing maliciously
    crafted web content may lead to universal cross site scripting.

    CVE-2020-9806

    Wen Xu discovered that processing maliciously crafted web content
    may lead to arbitrary code execution.

    CVE-2020-9807

    Wen Xu discovered that processing maliciously crafted web content
    may lead to arbitrary code execution.

    CVE-2020-9843

    Ryan Pickren discovered that processing maliciously crafted web
    content may lead to a cross site scripting attack.

    CVE-2020-9850

    @jinmo123, @setuid0x0_, and @insu_yun_en discovered that a remote
    attacker may be able to cause arbitrary code execution.

    CVE-2020-13753

    Milan Crha discovered that an attacker may be able to execute
    commands outside the bubblewrap sandbox.

    For the stable distribution (buster), these problems have been fixed in
    version 2.28.3-2~deb10u1.

    We recommend that you upgrade your webkit2gtk packages.

    For the detailed security status of webkit2gtk please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl8PaKUACgkQEMKTtsN8 Tjaf3hAAjZCKrikC4P1I/xiuL6kRepTjURi3zeZl3YywPCFLi/irWXX+5U+ejZoM kek3wtdJc1thN8w9BbXhOVyLferb/xfnt5jUVtZ6JBNDKKWGXoTY0Qfdu2lH0vw5 IV1lf5bvOdawrw/tVS9Uy3dTN1kXEBZ3q3XCpRXrBWEkrXtWG/yznGy0duebnI5h PM7D6R4PIKiCB3HBe9rszCIQrYcGQ/U3x8a/FPnPUO2TCRfVZG918M9yO1fN1v2R +08h0DcOU8ggIJQwJA9hm/V3mJWpTayHh/ouTI8PrIcwG0T2/qbtUm/9cj0wvmXW Id+RgXtQAyKeXQoXD5oP9jzVDgmm7rn03Rn2FX5hzAdTJAqdvT/Mr4IDNcOgdS8O wXmGprdRvMzx0gXO5YpeTuhjQiCZS1fB9ByIOMq/7lIjpiBctrhTZQvlSMMyauIQ P7tTTT8zCZo0DIQc/c2KyCXlD9/ORZm801U5wpXwPXT9Zq8wRAp5PodK/4plOzKc JyJiPI6BR41+31C438nl3wifO/wLh8+6nHAb2rkRQSe6Tu9SKyqOmYT9Ev6JZi/1 R8NMBFSmTYM/XUv5ECsTeL3uLvDnCpKAR0EnWz5z1Cqy2AYzEthEf+1dwXAooYvO 2johOWMaUrSWJMsYdZjTFEahaCSO5oPTDlbZCB2yIgpc6P70irU=
    =L5lA
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)