MGASA-2022-0059

Source
https://advisories.mageia.org/MGASA-2022-0059.html
Import Source
https://advisories.mageia.org/MGASA-2022-0059.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0059
Related
Published
2022-02-12T17:31:35Z
Modified
2022-02-12T16:48:56Z
Summary
Updated webkit2 packages fix security vulnerability
Details

Processing a maliciously crafted mail message may lead to running arbitrary javascript. Description: A validation issue was addressed with improved input sanitization. (CVE-2022-22589)

Processing maliciously crafted web content may lead to arbitrary code execution. Description: A use after free issue was addressed with improved memory management. (CVE-2022-22590)

Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Description: A logic issue was addressed with improved state management. (CVE-2022-22592)

References
Credits

Affected packages

Mageia:8 / webkit2

Package

Name
webkit2
Purl
pkg:rpm/mageia/webkit2?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.34.5-1.mga8

Ecosystem specific

{
    "section": "core"
}