You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa webkit2gtk

Sigurnosni nedostaci programskog paketa webkit2gtk

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3166-1
January 10, 2017

webkit2gtk vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in WebKitGTK+.

Software Description:
– webkit2gtk: JavaScript engine library from WebKitGTK+ – GObject introspection

Details:

A large number of security issues were discovered in the WebKitGTK+ Web and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of service
attacks, and arbitrary code execution.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
libjavascriptcoregtk-4.0-18 2.14.2-0ubuntu0.16.04.1
libwebkit2gtk-4.0-37 2.14.2-0ubuntu0.16.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK+, such as Epiphany, to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3166-1
CVE-2016-4613, CVE-2016-4657, CVE-2016-4666, CVE-2016-4707,
CVE-2016-4728, CVE-2016-4733, CVE-2016-4734, CVE-2016-4735,
CVE-2016-4759, CVE-2016-4760, CVE-2016-4761, CVE-2016-4762,
CVE-2016-4764, CVE-2016-4765, CVE-2016-4767, CVE-2016-4768,
CVE-2016-4769, CVE-2016-7578

Package Information:
https://launchpad.net/ubuntu/+source/webkit2gtk/2.14.2-0ubuntu0.16.04.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJYdTeTAAoJEGVp2FWnRL6TIp4QALV34cZSwrNEaTnOUOeahFvY
MfPclemSK0kCYc64vq4hYUDHkpC3AwF/njTQM0Z2S3nE+8z1jmOr/duDdrmjseLL
lDOUVDBliOdGO5OSc2pgU1S1GJY8fK0bEI39yfo3MHNuT81SXlFsoymFSL82+mUB
walS5XB9UzuUuPrgXbQAQ7yhXHgPs3gDPlQXOBs1rPnXw+Avx+EONZZxquOesxyE
eBWZxGRibdpCyzLa+HUrDUyedAMWp7nw7RirBhOo8saI+3HlziVQsB8ZIq3+onFg
QZZkLGI5dUXpyHtzu1TJiaFbJh1CHRK9mowBNqAcogrwIfnKjkb4Wl3QBjXlfaPy
pYupAcqx0WDPRHTW6oJvM+TDPmZFoVz0cktVvFAC8uLqD3XpmOH9N7VRpTQakTN9
6B/8dUm6kbhfRgBut9PIcbWRBZy70+WysiRbNSCzEqlwoL3Eqd8rLsfHW/sU3PEB
vMTnGqsZzfclvz3ZelWdgaqMlFUqg+8QNBOmMSKDirvUdhmlrPXkNXy48yNZWkR6
KEl67dO1fY33r5K5bp9jFd25/UcPmdjEjLFNkBJfHax4VYBgPUbUOXvwdS3PdU5J
g5BEBkXr3FYaAAG8/zA/Kf52/gb6X9GYcC9cvJbE80cNJWomE/YdebbF6mhRFNNA
iOdoZcEqyej7tro4sTs3
=l/Qm
—–END PGP SIGNATURE—–

AutorVlatka Misic
Cert idNCERT-REF-2017-01-0009-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostatak jezgre operacijskog sustava

Otkriven je sigurnosni nedostatak u programskom paketu kernel za operacijski sustav Redhat. Otkriveni nedostatak potencijalnim udaljenim napadačima omogućuje izmjenu podataka...

Close