MGASA-2020-0441

Source
https://advisories.mageia.org/MGASA-2020-0441.html
Import Source
https://advisories.mageia.org/MGASA-2020-0441.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0441
Related
Published
2020-11-27T20:14:57Z
Modified
2020-12-01T10:21:14Z
Summary
Updated webkit2 packages fix security vulnerabilities
Details

The webkit2 package has been updated to version 2.30.3, fixing several security issues and other bugs.

A type confusion issue may lead to arbitrary code execution with a maliciously crafted web content, fixed with improved memory handling (CVE-2020-9948).

An use after free issue may lead to arbitrary code execution with a maliciously crafted web content, fixed with improved memory management (CVE-2020-9951).

An out-of-bounds write issue may lead to code execution with a maliciously crafted web content, fixed with improved bounds checking (CVE-2020-9983).

An use after free issue may lead to arbitrary code execution with a maliciously crafted web content, fixed with improved memory management (CVE-2020-13543).

An use after free issue may lead to arbitrary code execution with a maliciously crafted web content, fixed with improved memory management. (CVE-2020-13584).

References
Credits

Affected packages

Mageia:7 / webkit2

Package

Name
webkit2
Purl
pkg:rpm/mageia/webkit2?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.30.3-1.mga7

Ecosystem specific

{
    "section": "core"
}