Summary: | <net-libs/webkit-gtk-2.30.3: multiple vulnerabilities (CVE-2020-{9948,9951,9952,9983,13543,13584}, WSA-2020-0008, WSA-2020-0009) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | gnome |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://mail.gnome.org/archives/gnome-announce-list/2020-November/msg00000.html | ||
Whiteboard: | A2 [glsa+ cve] | ||
Package list: |
dev-libs/libmanette-0.2.4 arm64
gui-libs/libwpe-1.8.0 amd64 arm64 x86
gui-libs/wpebackend-fdo-1.8.0 amd64 arm64 x86
net-libs/webkit-gtk-2.30.3 amd64 arm64 x86
|
Runtime testing required: | --- |
Bug Depends on: | 751271 | ||
Bug Blocks: |
Description
John Helmert III
2020-11-21 14:16:23 UTC
Actually, this has turned out to be a number of more serious vulnerabilities. CVE-2020-13584: Processing maliciously crafted web content may lead to arbitrary code execution. Description: An use after free issue was addressed with improved memory management. CVE-2020-9948: Processing maliciously crafted web content may lead to arbitrary code execution. Description: A type confusion issue was addressed with improved memory handling. CVE-2020-9951: Processing maliciously crafted web content may lead to arbitrary code execution. Description: An use after free issue was addressed with improved memory management. CVE-2020-9952: Processing maliciously crafted web content may lead to a cross site scripting attack. Description: An input validation issue was addressed with improved input validation. CVE-2020-9983: Processing maliciously crafted web content may lead to code execution. Description: An out-of-bounds write issue was addressed with improved bounds checking. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fd0355d8d21f68237792e427dbe3da433ee66f82 commit fd0355d8d21f68237792e427dbe3da433ee66f82 Author: Mart Raudsepp <leio@gentoo.org> AuthorDate: 2020-11-26 22:39:31 +0000 Commit: Mart Raudsepp <leio@gentoo.org> CommitDate: 2020-11-26 22:39:44 +0000 net-libs/webkit-gtk: security bump to 2.30.3 Bug: https://bugs.gentoo.org/755947 Closes: https://bugs.gentoo.org/751943 Closes: https://bugs.gentoo.org/751271 Package-Manager: Portage-2.3.103, Repoman-2.3.20 Signed-off-by: Mart Raudsepp <leio@gentoo.org> net-libs/webkit-gtk/Manifest | 1 + net-libs/webkit-gtk/files/2.30.3-icu68.patch | 179 ++++++++++++++++ net-libs/webkit-gtk/metadata.xml | 1 + net-libs/webkit-gtk/webkit-gtk-2.30.3.ebuild | 296 +++++++++++++++++++++++++++ profiles/arch/sparc/package.use.mask | 4 + 5 files changed, 481 insertions(+) Thanks! Please stabilize when ready. Sanity check failed:
> net-libs/webkit-gtk-2.30.3
> depend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (3 total)
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
> depend amd64 stable profile default/linux/amd64/17.1 (25 total)
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
> rdepend amd64 dev profile default/linux/amd64/17.0/no-multilib/prefix/kernel-3.2+ (3 total)
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
> rdepend amd64 stable profile default/linux/amd64/17.1 (25 total)
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
> depend arm64 stable profile default/linux/arm64/17.0 (9 total)
> >=dev-libs/libmanette-0.2.4
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
> rdepend arm64 stable profile default/linux/arm64/17.0 (9 total)
> >=dev-libs/libmanette-0.2.4
> >=gui-libs/libwpe-1.5.0:1.0
> >=gui-libs/wpebackend-fdo-1.7.0:1.0
This is awaiting some USE combo tests that Sam is doing as noted in bug 751271. If it looks good for him, he may CC arches himself (and probably push some of the stablings). Sanity check failed:
> net-libs/webkit-gtk-2.30.3
> depend arm64 stable profile default/linux/arm64/17.0 (9 total)
> >=dev-libs/libmanette-0.2.4
> rdepend arm64 stable profile default/linux/arm64/17.0 (9 total)
> >=dev-libs/libmanette-0.2.4
All sanity-check issues have been resolved Another advisory: https://webkitgtk.org/security/WSA-2020-0009.html CVE-2020-13543/WSA-2020-0009.html: Processing maliciously crafted web content may lead to arbitrary code execution. Description: An use after free issue was addressed with improved memory management. amd64 done arm64 done x86 stable The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=52a65460e664cb123bd3d81af26473d0b6e4a20b commit 52a65460e664cb123bd3d81af26473d0b6e4a20b Author: Mart Raudsepp <leio@gentoo.org> AuthorDate: 2020-12-04 11:52:10 +0000 Commit: Mart Raudsepp <leio@gentoo.org> CommitDate: 2020-12-04 11:52:10 +0000 net-libs/webkit-gtk: security cleanup Bug: https://bugs.gentoo.org/755947 Package-Manager: Portage-3.0.10, Repoman-3.0.2 Signed-off-by: Mart Raudsepp <leio@gentoo.org> net-libs/webkit-gtk/Manifest | 1 - net-libs/webkit-gtk/webkit-gtk-2.28.4.ebuild | 290 --------------------------- 2 files changed, 291 deletions(-) (In reply to Larry the Git Cow from comment #12) > The bug has been referenced in the following commit(s): > > https://gitweb.gentoo.org/repo/gentoo.git/commit/ > ?id=52a65460e664cb123bd3d81af26473d0b6e4a20b > > commit 52a65460e664cb123bd3d81af26473d0b6e4a20b > Author: Mart Raudsepp <leio@gentoo.org> > AuthorDate: 2020-12-04 11:52:10 +0000 > Commit: Mart Raudsepp <leio@gentoo.org> > CommitDate: 2020-12-04 11:52:10 +0000 > > net-libs/webkit-gtk: security cleanup > > Bug: https://bugs.gentoo.org/755947 > Package-Manager: Portage-3.0.10, Repoman-3.0.2 > Signed-off-by: Mart Raudsepp <leio@gentoo.org> > > net-libs/webkit-gtk/Manifest | 1 - > net-libs/webkit-gtk/webkit-gtk-2.28.4.ebuild | 290 > --------------------------- > 2 files changed, 291 deletions(-) Thank you! New GLSA request filed. This issue was resolved and addressed in GLSA 202012-10 at https://security.gentoo.org/glsa/202012-10 by GLSA coordinator Thomas Deutschmann (whissi). |