Summary: | <net-libs/webkit-gtk-2.16.3: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | gnome |
Priority: | Normal | Flags: | stable-bot:
sanity-check+
|
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://webkitgtk.org/security/WSA-2017-0004.html | ||
Whiteboard: | B2 [glsa cve] | ||
Package list: |
net-libs/webkit-gtk-2.16.3
|
Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
2017-05-26 21:43:02 UTC
https://webkitgtk.org/security/WSA-2017-0004.html WebKitGTK+ Security Advisory WSA-2017-0004 Date Reported: May 25, 2017 Advisory ID: WSA-2017-0004 CVE identifiers: CVE-2017-2496, CVE-2017-2504, CVE-2017-2505, CVE-2017-2506, CVE-2017-2508, CVE-2017-2510, CVE-2017-2514, CVE-2017-2515, CVE-2017-2521, CVE-2017-2525, CVE-2017-2526, CVE-2017-2528, CVE-2017-2530, CVE-2017-2531, CVE-2017-2536, CVE-2017-2539, CVE-2017-2544, CVE-2017-2547, CVE-2017-2549, CVE-2017-6980, CVE-2017-6984. Several vulnerabilities were discovered in WebKitGTK+. CVE-2017-2496 Versions affected: WebKitGTK+ before 2.16.3. Credit to Apple. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2504 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to universal cross site scripting (UXSS). Description: A logic issue existed in the handling of WebKit Editor commands. This issue was addressed with improved state management. CVE-2017-2505 Versions affected: WebKitGTK+ before 2.16.0. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2506 Versions affected: WebKitGTK+ before 2.16.1. Credit to Zheng Huang of the Baidu Security Lab working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2508 Versions affected: WebKitGTK+ before 2.16.0. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to universal cross site scripting (UXSS). Description: A logic issue existed in the handling of WebKit container nodes. This issue was addressed with improved state management. CVE-2017-2510 Versions affected: WebKitGTK+ before 2.16.3. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to universal cross site scripting (UXSS). Description: A logic issue existed in the handling of pageshow events. This issue was addressed with improved state management. CVE-2017-2514 Versions affected: WebKitGTK+ before 2.16.0. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2515 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2521 Versions affected: WebKitGTK+ before 2.16.0. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2525 Versions affected: WebKitGTK+ before 2.16.1. Credit to Kai Kang (4B5F5F4B) of Tencent’s Xuanwu Lab (tencent.com) working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2526 Versions affected: WebKitGTK+ before 2.16.1. Credit to Kai Kang (4B5F5F4B) of Tencent’s Xuanwu Lab (tencent.com) working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2528 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to universal cross site scripting (UXSS). Description: A logic issue existed in the handling of WebKit cached frames. This issue was addressed with improved state management. CVE-2017-2530 Versions affected: WebKitGTK+ before 2.16.1. Credit to Wei Yuan of Baidu Security Lab. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2531 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2536 Versions affected: WebKitGTK+ before 2.16.1. Credit to Samuel Groß and Niklas Baumstark working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2539 Versions affected: WebKitGTK+ before 2.16.3. Credit to Richard Zhu (fluorescence) working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2544 Versions affected: WebKitGTK+ before 2.16.1. Credit to 360 Security (@mj0011sec) working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2547 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero, Team Sniper (Keen Lab and PC Mgr) working with Trend Micro’s Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-2549 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to universal cross site scripting (UXSS). Description: A logic issue existed in frame loading. This issue was addressed with improved state management. CVE-2017-6980 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2017-6984 Versions affected: WebKitGTK+ before 2.16.1. Credit to lokihardt of Google Project Zero. Impact: Processing maliciously crafted web content may lead to arbitrary code execution or cause a denial of service (memory corruption and application crash). Description: Multiple memory corruption issues were addressed with improved memory handling. Arches please proceed as already CCed in earlier action :) commit 699d560d397993025482777d1ddd3e403859d437 Author: Mart Raudsepp <leio@gentoo.org> Date: Sat May 27 00:40:39 2017 +0300 net-libs/webkit-gtk: bump to 2.16.3; includes 3 security bug fixes Security fixes: CVE-2017-2496, CVE-2017-2539, CVE-2017-2510. Also other bug fixes. amd64 stable x86 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one. Cleanup of SLOT=4 done; earlier slots can not be cleaned up as usual due to consumers. Added to an existing GLSA. This issue was resolved and addressed in GLSA 201706-15 at https://security.gentoo.org/glsa/201706-15 by GLSA coordinator Thomas Deutschmann (whissi). Cleanup for older slots are tracked in bug 577068. |