Advisories ยป MGASA-2020-0441

Updated webkit2 packages fix security vulnerabilities

Publication date: 27 Nov 2020
Modification date: 01 Dec 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-9948 , CVE-2020-9951 , CVE-2020-9983 , CVE-2020-13543 , CVE-2020-13584

Description

The webkit2 package has been updated to version 2.30.3, fixing several
security issues and other bugs.

A type confusion issue may lead to arbitrary code execution with a maliciously
crafted web content, fixed with improved memory handling (CVE-2020-9948).

An use after free issue may lead to arbitrary code execution with a maliciously
crafted web content, fixed with improved memory management (CVE-2020-9951).

An out-of-bounds write issue may lead to code execution with a maliciously
crafted web content, fixed with improved bounds checking (CVE-2020-9983).

An use after free issue may lead to arbitrary code execution with a maliciously
crafted web content, fixed with improved memory management (CVE-2020-13543).

An use after free issue may lead to arbitrary code execution with a maliciously
crafted web content, fixed with improved memory management. (CVE-2020-13584).
                

References

SRPMS

7/core