Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 636378 (CVE-2017-1000121, CVE-2017-1000122) - net-libs/webkit-gtk: Multiple vulnerabilities (CVE-2017-{1000121,1000122})
Summary: net-libs/webkit-gtk: Multiple vulnerabilities (CVE-2017-{1000121,1000122})
Status: RESOLVED FIXED
Alias: CVE-2017-1000121, CVE-2017-1000122
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://webkitgtk.org/security/WSA-20...
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-03 14:13 UTC by GLSAMaker/CVETool Bot
Modified: 2017-11-03 14:29 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-03 14:13:49 UTC
CVE-2017-1000122 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000122):
  The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not
  properly validate certain message metadata, allowing a compromised secondary
  process to cause a denial of service (release assertion) of the UI process.
  This vulnerability does not affect Apple products.

CVE-2017-1000121 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000121):
  The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not
  properly validate message size metadata, allowing a compromised secondary
  process to trigger an integer overflow and subsequent buffer overflow in the
  UI process. This vulnerability does not affect Apple products.
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-03 14:14:51 UTC
@Maintainers please confirm if we are affected by this vulnerabilities.

Thank you.
Comment 2 Mart Raudsepp gentoo-dev 2017-11-03 14:25:03 UTC
2.16.3 and newer is safe per https://webkitgtk.org/security/WSA-2017-0007.html
Comment 3 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-03 14:29:17 UTC
Thank you, nothing else to do here then.

GLSA Vote: No