Advisories ยป MGASA-2022-0059

Updated webkit2 packages fix security vulnerability

Publication date: 12 Feb 2022
Modification date: 12 Feb 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-22589 , CVE-2022-22590 , CVE-2022-22592

Description

Processing a maliciously crafted mail message may lead to running arbitrary
javascript. Description: A validation issue was addressed with improved
input sanitization. (CVE-2022-22589)

Processing maliciously crafted web content may lead to arbitrary code
execution. Description: A use after free issue was addressed with
improved memory management. (CVE-2022-22590)

Processing maliciously crafted web content may prevent Content Security
Policy from being enforced. Description: A logic issue was addressed with
improved state management. (CVE-2022-22592)
                

References

SRPMS

8/core