Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 686216 (CVE-2019-8595, CVE-2019-8607, CVE-2019-8615) - <net-libs/webkit-gtk-2.24.2: multiple vulnerabilities
Summary: <net-libs/webkit-gtk-2.24.2: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2019-8595, CVE-2019-8607, CVE-2019-8615
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://webkitgtk.org/2019/05/17/webk...
Whiteboard: A3 [glsa+ cve]
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2019-05-18 12:16 UTC by D'juan McDonald (domhnall)
Modified: 2019-09-06 16:18 UTC (History)
1 user (show)

See Also:
Package list:
net-libs/webkit-gtk-2.24.2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description D'juan McDonald (domhnall) 2019-05-18 12:16:07 UTC
Security fixes [for]: CVE-2019-8595, CVE-2019-8607, CVE-2019-8615.

CVE-2019-8595
Multiple memory corruption issues were addressed with improved memory handling.

CVE-2019-8607
An out-of-bounds read was addressed with improved input validation.

CVE-2019-8615
Multiple memory corruption issues were addressed with improved memory handling.



Gentoo Security Padawan
(domhnall)
Comment 1 Thomas Deutschmann gentoo-dev Security 2019-05-19 13:19:44 UTC
x86 stable
Comment 2 Mikle Kolyada archtester Gentoo Infrastructure gentoo-dev Security 2019-05-19 19:58:31 UTC
amd64 stable
Comment 3 Mikle Kolyada archtester Gentoo Infrastructure gentoo-dev Security 2019-05-19 20:01:51 UTC
amd64 stable
Comment 4 Thomas Deutschmann gentoo-dev Security 2019-09-06 15:44:19 UTC
Added to an existing GLSA.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2019-09-06 16:18:37 UTC
This issue was resolved and addressed in
 GLSA 201909-05 at https://security.gentoo.org/glsa/201909-05
by GLSA coordinator Thomas Deutschmann (whissi).