|
|
Subscribe / Log in / New account

webkit2gtk: multiple vulnerabilities

Package(s):webkit2gtk CVE #(s):CVE-2017-2350 CVE-2017-2354 CVE-2017-2355 CVE-2017-2356 CVE-2017-2362 CVE-2017-2363 CVE-2017-2364 CVE-2017-2365 CVE-2017-2366 CVE-2017-2369 CVE-2017-2371 CVE-2017-2373
Created:February 13, 2017 Updated:February 17, 2017
Description: From the Arch Linux advisory:

- CVE-2017-2350 (information disclosure): A security issue has been found in WebKitGTK+ before 2.14.4, where processing maliciously crafted web content may exfiltrate data cross- origin.

- CVE-2017-2354 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2355 (arbitrary code execution): A memory initialization issue has been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2356 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2362 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2363 (information disclosure): Multiple validation issues have been found in the handling of page loading in WebKitGTK+ before 2.14.4, leading to cross-origin data exfiltration while processing maliciously crafted web content.

- CVE-2017-2364 (information disclosure): Multiple validation issues have been found in the handling of page loading in WebKitGTK+ before 2.14.4, leading to cross-origin data exfiltration while processing maliciously crafted web content.

- CVE-2017-2365 (information disclosure): A validation issue has been found in variable handling in WebKitGTK+ before 2.14.4, leading to cross-origin data exfiltration while processing maliciously crafted web content.

- CVE-2017-2366 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2369 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

- CVE-2017-2371 (access restriction bypass): An issue has been found in the handling of blocking popups in WebKitGTK+ before 2.14.4, allowing a malicious website to open popups.

- CVE-2017-2373 (arbitrary code execution): Several memory corruption issues have been found in WebKitGTK+ before 2.14.4, leading to arbitrary code execution while processing maliciously crafted web content.

See the WebKitGTK+ Security Advisory WSA-2017-0002 for additional information.

Alerts:
Ubuntu USN-3200-1 webkit2gtk 2017-02-16
Arch Linux ASA-201702-9 webkit2gtk 2017-02-11

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds