Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 755947 (CVE-2020-13584, CVE-2020-9948, CVE-2020-9951, CVE-2020-9952, CVE-2020-9983, WSA-2020-0008) - <net-libs/webkit-gtk-2.20.3: multiple vulnerabilities (CVE-2020-{9948,9951,9952,9983,13584}, WSA-2020-0008)
Summary: <net-libs/webkit-gtk-2.20.3: multiple vulnerabilities (CVE-2020-{9948,9951,99...
Status: IN_PROGRESS
Alias: CVE-2020-13584, CVE-2020-9948, CVE-2020-9951, CVE-2020-9952, CVE-2020-9983, WSA-2020-0008
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://mail.gnome.org/archives/gnome...
Whiteboard: A2 [stable]
Keywords: CC-ARCHES
Depends on: 751271
Blocks:
  Show dependency tree
 
Reported: 2020-11-21 14:16 UTC by John Helmert III (ajak)
Modified: 2020-11-28 14:02 UTC (History)
4 users (show)

See Also:
Package list:
dev-libs/libmanette-0.2.4 arm64 gui-libs/libwpe-1.8.0 amd64 arm64 x86 gui-libs/wpebackend-fdo-1.8.0 amd64 arm64 x86 net-libs/webkit-gtk-2.30.3 amd64 arm64 x86
Runtime testing required: ---
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III (ajak) 2020-11-21 14:16:23 UTC
In the changelog for webkit-gtk 2.30.3:

  - Fix several crashes and rendering issues.


Presumably these are security-relevant fixes, so please bump.
Comment 1 John Helmert III (ajak) 2020-11-23 20:52:14 UTC
Actually, this has turned out to be a number of more serious vulnerabilities.


CVE-2020-13584:

Processing maliciously crafted web content may lead to arbitrary code execution. Description: An use after free issue was addressed with improved memory management.

CVE-2020-9948:

Processing maliciously crafted web content may lead to arbitrary code execution. Description: A type confusion issue was addressed with improved memory handling.

CVE-2020-9951:

Processing maliciously crafted web content may lead to arbitrary code execution. Description: An use after free issue was addressed with improved memory management.

CVE-2020-9952:

Processing maliciously crafted web content may lead to a cross site scripting attack. Description: An input validation issue was addressed with improved input validation.

CVE-2020-9983:

Processing maliciously crafted web content may lead to code execution. Description: An out-of-bounds write issue was addressed with improved bounds checking.
Comment 2 Larry the Git Cow gentoo-dev 2020-11-26 22:40:52 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fd0355d8d21f68237792e427dbe3da433ee66f82

commit fd0355d8d21f68237792e427dbe3da433ee66f82
Author:     Mart Raudsepp <leio@gentoo.org>
AuthorDate: 2020-11-26 22:39:31 +0000
Commit:     Mart Raudsepp <leio@gentoo.org>
CommitDate: 2020-11-26 22:39:44 +0000

    net-libs/webkit-gtk: security bump to 2.30.3
    
    Bug: https://bugs.gentoo.org/755947
    Closes: https://bugs.gentoo.org/751943
    Closes: https://bugs.gentoo.org/751271
    Package-Manager: Portage-2.3.103, Repoman-2.3.20
    Signed-off-by: Mart Raudsepp <leio@gentoo.org>

 net-libs/webkit-gtk/Manifest                 |   1 +
 net-libs/webkit-gtk/files/2.30.3-icu68.patch | 179 ++++++++++++++++
 net-libs/webkit-gtk/metadata.xml             |   1 +
 net-libs/webkit-gtk/webkit-gtk-2.30.3.ebuild | 296 +++++++++++++++++++++++++++
 profiles/arch/sparc/package.use.mask         |   4 +
 5 files changed, 481 insertions(+)
Comment 3 John Helmert III (ajak) 2020-11-26 22:44:54 UTC
Thanks! Please stabilize when ready.
Comment 4 NATTkA bot gentoo-dev 2020-11-26 22:49:01 UTC Comment hidden (obsolete)
Comment 5 Mart Raudsepp gentoo-dev 2020-11-27 09:08:42 UTC
This is awaiting some USE combo tests that Sam is doing as noted in bug 751271. If it looks good for him, he may CC arches himself (and probably push some of the stablings).
Comment 6 NATTkA bot gentoo-dev 2020-11-27 09:12:56 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2020-11-27 09:21:00 UTC
All sanity-check issues have been resolved