From 441d1370330332b7d78f238d2f5e13f7aed5e4e0 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 25 Dec 2020 23:06:25 +0000 Subject: gentoo christmass resync : 25.12.2020 --- metadata/glsa/glsa-202012-10.xml | 60 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 metadata/glsa/glsa-202012-10.xml (limited to 'metadata/glsa/glsa-202012-10.xml') diff --git a/metadata/glsa/glsa-202012-10.xml b/metadata/glsa/glsa-202012-10.xml new file mode 100644 index 000000000000..d3fcad05f767 --- /dev/null +++ b/metadata/glsa/glsa-202012-10.xml @@ -0,0 +1,60 @@ + + + + WebkitGTK+: Multiple vulnerabilities + Multiple vulnerabilities have been found in WebKitGTK+, the worst + of which could result in the arbitrary execution of code. + + webkit-gtk + 2020-12-23 + 2020-12-23 + 755947 + remote + + + 2.30.3 + 2.30.3 + + + +

WebKitGTK+ is a full-featured port of the WebKit rendering engine, + suitable for projects requiring any kind of web integration, from hybrid + HTML/CSS applications to full-fledged web browsers. +

+
+ +

Multiple vulnerabilities have been discovered in WebKitGTK+. Please + review the CVE identifiers referenced below for details. +

+
+ +

An attacker, by enticing a user to visit maliciously crafted web + content, may be able to execute arbitrary code or cause memory + corruption. +

+
+ +

There is no known workaround at this time.

+
+ +

All WebkitGTK+ users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.30.3" + + +
+ + CVE-2020-13543 + CVE-2020-13584 + CVE-2020-9948 + CVE-2020-9951 + CVE-2020-9952 + CVE-2020-9983 + WSA-2020-0008 + WSA-2020-0009 + + whissi + whissi +
-- cgit v1.2.3