Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2022.5789 webkit2gtk security update 10 November 2022 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: webkit2gtk Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2022-42824 CVE-2022-42823 CVE-2022-42799 Original Bulletin: https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html Comment: CVSS (Max): 8.8 CVE-2022-42823 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) CVSS Source: NVD Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3183-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort November 09, 2022 https://wiki.debian.org/LTS - - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.38.2-1~deb10u1 CVE ID : CVE-2022-42799 CVE-2022-42823 CVE-2022-42824 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42799 Jihwan Kim and Dohyun Lee discovered that visiting a malicious website may lead to user interface spoofing. CVE-2022-42823 Dohyun Lee discovered that processing maliciously crafted web content may lead to arbitrary code execution. CVE-2022-42824 Abdulrahman Alqabandi, Ryan Shin and Dohyun Lee discovered that processing maliciously crafted web content may disclose sensitive user information. For Debian 10 buster, these problems have been fixed in version 2.38.2-1~deb10u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmNrYnIACgkQnUbEiOQ2 gwLj3A/9E66Zfw9IOyJLtEJpaSoRXxQDEOybRt8B/7Aj73jP3WvsWrvwE/wY8487 R03nBubqfaQM8ALQC3mnFOF4/iNyppcOPkvTQ7ZbNbkNQOTIvs6S6t3eKlL3V9Xu p5K+U5u5/7J/z/YBmozGvoSTg/l8E5N8V4XVEHjylYYQE716vH5ow8RyTKJcsBf8 YXbrHIYK3cGUSjWjn8gTN8/29DIutkesTWVzRFtViBHIuLjw2XqswQQqDKR+9bCU zn1FNbZ/VoJ1nE0/VLHw+1/w25aaQY3eCEr90+APDOsJIsOljlwOAE3RqpCACym6 hAtnTB9M6SafrxVvwhGg2v2RRCyh+DLp9l1KojSUWRJpglq0ZimV+p2v2W5JpNnV phZVKDinq1OhFZe5UWy3fk43vCiZhWuzZ6LVZTHqoRvcS17lRDAJxY9qJKeH2L00 jZjHqxyue7/ov6T+9P2PeHYxZf2ea+PAex5iwAr6adlP5ZITSG+EHn4JUUjKtvEu V0CL2qdDP3TXMOBaZuNrm+5rLxAmTXh8FkFkPxlyLR8WKeu9j0X73d6ODVcjZhhB BOEchVExA7F8wB4K6U74RRbDzvirhvZV0xqmKzs3apnGGez5YTsGRXG2GRGVfaFU JzE72tdLL3oz+ZgpxICNR2/vf3t7hVSzpf3TK0AkNeS7nx3ltgs= =HXnx - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBY2yLKckNZI30y1K9AQjldw//XvFNWQNqRNcSotaZs6Pg3k4JxQPBpyqQ yZ7rFeBscUXwyIvNqhCCri4aVKGcsY4FWZmf4Ojvp/oZO0xuyfXFvn1Vbrrxee30 pGwF+P+Q88IzeU5s4jhtW42vkwqPzyvJMD4z4fK3iVk+EvdYuRM2962RekcuW4Kv RUB7Xovgq11RpyAd1slNxAMWChhx8WCC9emrFevPKL1vAOjbzMx5pn+DAJf+drYj 58rfZRf2bk39Z0PRUw9ZbbnW+ajpv1zvlkAq0zyORxq1vQZGQu6dR5r9ALntLD3/ TjA7yEUH9kWS5PzyrJd/ZA2gMWfSJwS8eFDdDy5vcgEX1vZQA8pe4zRyNDzhqtLj PDleFnO36lgwr02AuWa9qoKB3l0O080aJ5iQ3HpAf3OTocm1rKYuL8YXrwp56Qn2 OWDbp4AO7Ftrdv8MwoQDmKyBPqhVpFcOSbbtokz4CPOLUmCsyWlgFDsj/Ab3H+1o BrLmrBkuPR6myzZ65W3VcY8JdyYcFi6LcXDWTxoxzMGS2sHB+EtAh6E/s27Z67MV s1NR2TkgpVaqcFzFw66tHlqAdTNZVjAqVHdgZMRBWKddXO4fsW4rNffm9It8nqJ4 XjSS7KJ1COsEZx4o9dxlGlaKNC+IybL5uQye0dx5CeH/HY5xwtMPsbVCklASB7bw S2fhSbzW+OA= =E8mz -----END PGP SIGNATURE-----