[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2024-0008

Alberto Garcia (@berto) berto at debian.org
Mon Dec 23 22:08:22 GMT 2024



Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8ac7528e by Alberto Garcia at 2024-12-23T23:08:04+01:00
webkit2gtk / wpewebkit upstream advisory WSA-2024-0008

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2251,7 +2251,11 @@ CVE-2024-55657 (SiYuan is a personal knowledge management system. Prior to versi
 CVE-2024-55652 (PenDoc is a penetration testing reporting application. Prior to commit ...)
 	NOT-FOR-US: PenDoc
 CVE-2024-54534 (The issue was addressed with improved memory handling. This issue is f ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.0-1
+	- wpewebkit 2.46.0-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0008.html
 CVE-2024-54531 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2024-54529 (A logic issue was addressed with improved checks. This issue is fixed  ...)
@@ -2273,17 +2277,29 @@ CVE-2024-54513 (A permissions issue was addressed with additional restrictions.
 CVE-2024-54510 (A race condition was addressed with improved locking. This issue is fi ...)
 	NOT-FOR-US: Apple
 CVE-2024-54508 (The issue was addressed with improved memory handling. This issue is f ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.5-1
+	- wpewebkit 2.46.5-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0008.html
 CVE-2024-54506 (An out-of-bounds access issue was addressed with improved bounds check ...)
 	NOT-FOR-US: Apple
 CVE-2024-54505 (A type confusion issue was addressed with improved memory handling. Th ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.5-1
+	- wpewebkit 2.46.5-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0008.html
 CVE-2024-54504 (A privacy issue was addressed with improved private data redaction for ...)
 	NOT-FOR-US: Apple
 CVE-2024-54503 (An inconsistent user interface issue was addressed with improved state ...)
 	NOT-FOR-US: Apple
 CVE-2024-54502 (The issue was addressed with improved checks. This issue is fixed in w ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.5-1
+	- wpewebkit 2.46.5-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0008.html
 CVE-2024-54501 (The issue was addressed with improved checks. This issue is fixed in i ...)
 	NOT-FOR-US: Apple
 CVE-2024-54500 (The issue was addressed with improved checks. This issue is fixed in i ...)
@@ -2311,7 +2327,11 @@ CVE-2024-54485 (The issue was addressed by adding additional logic. This issue i
 CVE-2024-54484 (The issue was resolved by sanitizing logging. This issue is fixed in m ...)
 	NOT-FOR-US: Apple
 CVE-2024-54479 (The issue was addressed with improved checks. This issue is fixed in i ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.5-1
+	- wpewebkit 2.46.5-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0008.html
 CVE-2024-54477 (The issue was addressed with improved checks. This issue is fixed in m ...)
 	NOT-FOR-US: Apple
 CVE-2024-54476 (The issue was addressed with improved checks. This issue is fixed in m ...)


=====================================
data/DSA/list
=====================================
@@ -129,7 +129,7 @@
 	{CVE-2024-9954 CVE-2024-9955 CVE-2024-9956 CVE-2024-9957 CVE-2024-9958 CVE-2024-9959 CVE-2024-9960 CVE-2024-9961 CVE-2024-9962 CVE-2024-9963 CVE-2024-9964 CVE-2024-9965 CVE-2024-9966}
 	[bookworm] - chromium 130.0.6723.58-1~deb12u1
 [14 Oct 2024] DSA-5792-1 webkit2gtk - security update
-	{CVE-2024-40866 CVE-2024-44185 CVE-2024-44187}
+	{CVE-2024-40866 CVE-2024-44185 CVE-2024-44187 CVE-2024-54534}
 	[bookworm] - webkit2gtk 2.46.0-2~deb12u1
 [13 Oct 2024] DSA-5791-1 python-reportlab - security update
 	{CVE-2023-33733}


=====================================
data/dsa-needed.txt
=====================================
@@ -52,6 +52,8 @@ tcpdf
 --
 trafficserver
 --
+webkit2gtk (berto)
+--
 wordpress
 --
 xen (jmm)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ac7528e0a12881652f4697d27b7c6efda86638c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ac7528e0a12881652f4697d27b7c6efda86638c
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20241223/ccfd985f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list