Bug 1066892 - VUL-0: webkit2gtk3: multiple security issues fixed
VUL-0: webkit2gtk3: multiple security issues fixed
Status: RESOLVED FIXED
: 1069925 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
CVSSv3:SUSE:CVE-2017-7094:9.8:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-07 11:46 UTC by Marcus Meissner
Modified: 2018-01-31 23:46 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2017-11-07 11:46:54 UTC
19/10/2017

CERT-IST/AV-2017.1118 V1.0

Vulnerabilities in the WebKitGTK+ HTML rendering library

high

• CVE: CVE-2017-7081
• CVE: CVE-2017-7087
• CVE: CVE-2017-7089
• CVE: CVE-2017-7090
• CVE: CVE-2017-7091
• CVE: CVE-2017-7092
• CVE: CVE-2017-7093
• CVE: CVE-2017-7094
• CVE: CVE-2017-7095
• CVE: CVE-2017-7096
• CVE: CVE-2017-7098
• CVE: CVE-2017-7099
• CVE: CVE-2017-7100
• CVE: CVE-2017-7102
• CVE: CVE-2017-7104
• CVE: CVE-2017-7107
• CVE: CVE-2017-7109
• CVE: CVE-2017-7111
• CVE: CVE-2017-7117
• CVE: CVE-2017-7120
• CVE: CVE-2017-7142





• WebKit HTML engine versions prior to 2.18.1 (affects in particular Qt, KDE, and Safari)
Comment 1 Scott Reeves 2017-11-08 00:23:22 UTC
Federico - can you take this.

2.18.2 is already in Factory so tumbleweed and SLE15 are done.

2.18.0 was accepted into SLE12 so just need the minor version bump.
Comment 2 Federico Mena Quintero 2017-11-21 22:42:34 UTC
I'll update this.
Comment 3 Federico Mena Quintero 2017-11-24 00:45:43 UTC
Submitted to SUSE:SLE-12-SP3:Update with id 147205.

Reassigning to security-team.
Comment 4 Federico Mena Quintero 2017-11-28 19:58:10 UTC
*** Bug 1069925 has been marked as a duplicate of this bug. ***
Comment 5 Federico Mena Quintero 2018-01-11 01:00:50 UTC
I think this bug can be closed now; we already have 2.18.1 (and even newer versions) on SLE12-SP3.
Comment 6 Marcus Meissner 2018-01-11 06:30:51 UTC
released
Comment 7 Swamp Workflow Management 2018-01-25 20:10:47 UTC
SUSE-SU-2018:0219-1: An update that fixes 89 vulnerabilities is now available.

Category: security (important)
Bug References: 1020950,1024749,1050469,1066892,1069925,1073654,1075419
CVE References: CVE-2016-4692,CVE-2016-4743,CVE-2016-7586,CVE-2016-7587,CVE-2016-7589,CVE-2016-7592,CVE-2016-7598,CVE-2016-7599,CVE-2016-7610,CVE-2016-7623,CVE-2016-7632,CVE-2016-7635,CVE-2016-7639,CVE-2016-7641,CVE-2016-7645,CVE-2016-7652,CVE-2016-7654,CVE-2016-7656,CVE-2017-13788,CVE-2017-13798,CVE-2017-13803,CVE-2017-13856,CVE-2017-13866,CVE-2017-13870,CVE-2017-2350,CVE-2017-2354,CVE-2017-2355,CVE-2017-2356,CVE-2017-2362,CVE-2017-2363,CVE-2017-2364,CVE-2017-2365,CVE-2017-2366,CVE-2017-2369,CVE-2017-2371,CVE-2017-2373,CVE-2017-2496,CVE-2017-2510,CVE-2017-2539,CVE-2017-5715,CVE-2017-5753,CVE-2017-5754,CVE-2017-7006,CVE-2017-7011,CVE-2017-7012,CVE-2017-7018,CVE-2017-7019,CVE-2017-7020,CVE-2017-7030,CVE-2017-7034,CVE-2017-7037,CVE-2017-7038,CVE-2017-7039,CVE-2017-7040,CVE-2017-7041,CVE-2017-7042,CVE-2017-7043,CVE-2017-7046,CVE-2017-7048,CVE-2017-7049,CVE-2017-7052,CVE-2017-7055,CVE-2017-7056,CVE-2017-7059,CVE-2017-7061,CVE-2017-7064,CVE-2017-7081,CVE-2017-7087,CVE-2017-7089,CVE-2017-7090,CVE-2017-7091,CVE-2017-7092,CVE-2017-7093,CVE-2017-7094,CVE-2017-7095,CVE-2017-7096,CVE-2017-7098,CVE-2017-7099,CVE-2017-7100,CVE-2017-7102,CVE-2017-7104,CVE-2017-7107,CVE-2017-7109,CVE-2017-7111,CVE-2017-7117,CVE-2017-7120,CVE-2017-7142,CVE-2017-7156,CVE-2017-7157
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP3 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Workstation Extension 12-SP2 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Server 12-SP3 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Server 12-SP2 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    webkit2gtk3-2.18.5-2.18.1
SUSE Linux Enterprise Desktop 12-SP2 (src):    webkit2gtk3-2.18.5-2.18.1
Comment 8 Swamp Workflow Management 2018-01-31 23:15:09 UTC
openSUSE-SU-2018:0326-1: An update that fixes 89 vulnerabilities is now available.

Category: security (important)
Bug References: 1020950,1024749,1050469,1066892,1069925,1073654,1075419
CVE References: CVE-2016-4692,CVE-2016-4743,CVE-2016-7586,CVE-2016-7587,CVE-2016-7589,CVE-2016-7592,CVE-2016-7598,CVE-2016-7599,CVE-2016-7610,CVE-2016-7623,CVE-2016-7632,CVE-2016-7635,CVE-2016-7639,CVE-2016-7641,CVE-2016-7645,CVE-2016-7652,CVE-2016-7654,CVE-2016-7656,CVE-2017-13788,CVE-2017-13798,CVE-2017-13803,CVE-2017-13856,CVE-2017-13866,CVE-2017-13870,CVE-2017-2350,CVE-2017-2354,CVE-2017-2355,CVE-2017-2356,CVE-2017-2362,CVE-2017-2363,CVE-2017-2364,CVE-2017-2365,CVE-2017-2366,CVE-2017-2369,CVE-2017-2371,CVE-2017-2373,CVE-2017-2496,CVE-2017-2510,CVE-2017-2539,CVE-2017-5715,CVE-2017-5753,CVE-2017-5754,CVE-2017-7006,CVE-2017-7011,CVE-2017-7012,CVE-2017-7018,CVE-2017-7019,CVE-2017-7020,CVE-2017-7030,CVE-2017-7034,CVE-2017-7037,CVE-2017-7038,CVE-2017-7039,CVE-2017-7040,CVE-2017-7041,CVE-2017-7042,CVE-2017-7043,CVE-2017-7046,CVE-2017-7048,CVE-2017-7049,CVE-2017-7052,CVE-2017-7055,CVE-2017-7056,CVE-2017-7059,CVE-2017-7061,CVE-2017-7064,CVE-2017-7081,CVE-2017-7087,CVE-2017-7089,CVE-2017-7090,CVE-2017-7091,CVE-2017-7092,CVE-2017-7093,CVE-2017-7094,CVE-2017-7095,CVE-2017-7096,CVE-2017-7098,CVE-2017-7099,CVE-2017-7100,CVE-2017-7102,CVE-2017-7104,CVE-2017-7107,CVE-2017-7109,CVE-2017-7111,CVE-2017-7117,CVE-2017-7120,CVE-2017-7142,CVE-2017-7156,CVE-2017-7157
Sources used:
openSUSE Leap 42.3 (src):    webkit2gtk3-2.18.5-8.1