[Git][security-tracker-team/security-tracker][master] webkit2gtk / wpewebkit upstream advisory WSA-2024-0005

Alberto Garcia (@berto) berto at debian.org
Thu Sep 26 10:18:34 BST 2024



Alberto Garcia pushed to branch master at Debian Security Tracker / security-tracker


Commits:
887b1501 by Alberto Garcia at 2024-09-26T11:18:02+02:00
webkit2gtk / wpewebkit upstream advisory WSA-2024-0005

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1695,7 +1695,12 @@ CVE-2024-44189 (The issue was addressed with improved checks. This issue is fixe
 CVE-2024-44188 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2024-44187 (A cross-origin issue existed with "iframe" elements. This was addresse ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.0-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit <unfixed>
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-44186 (An access issue was addressed with additional sandbox restrictions. Th ...)
 	NOT-FOR-US: Apple
 CVE-2024-44184 (A permissions issue was addressed with additional restrictions. This i ...)
@@ -1781,7 +1786,12 @@ CVE-2024-44125 (The issue was addressed with improved checks. This issue is fixe
 CVE-2024-44124 (This issue was addressed through improved state management. This issue ...)
 	NOT-FOR-US: Apple
 CVE-2024-40866 (The issue was addressed with improved UI. This issue is fixed in Safar ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.0-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit <unfixed>
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-40863 (This issue was addressed with improved data protection. This issue is  ...)
 	NOT-FOR-US: Apple
 CVE-2024-40862 (A privacy issue was addressed by removing sensitive data. This issue i ...)
@@ -1793,7 +1803,12 @@ CVE-2024-40860 (A logic issue was addressed with improved checks. This issue is
 CVE-2024-40859 (A permissions issue was addressed with additional restrictions. This i ...)
 	NOT-FOR-US: Apple
 CVE-2024-40857 (This issue was addressed through improved state management. This issue ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.46.0-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit <unfixed>
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-40856 (An integrity issue was addressed with Beacon Protection. This issue is ...)
 	NOT-FOR-US: Apple
 CVE-2024-40852 (This issue was addressed by restricting options offered on a locked de ...)
@@ -25614,9 +25629,19 @@ CVE-2024-27857 (An out-of-bounds access issue was addressed with improved bounds
 CVE-2024-27855 (The issue was addressed with improved checks. This issue is fixed in m ...)
 	NOT-FOR-US: Apple
 CVE-2024-27851 (The issue was addressed with improved bounds checks. This issue is fix ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.3-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.3-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27850 (This issue was addressed with improvements to the noise injection algo ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.2-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.2-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27848 (This issue was addressed with improved permissions checking. This issu ...)
 	NOT-FOR-US: Apple
 CVE-2024-27845 (A privacy issue was addressed with improved handling of temporary file ...)
@@ -25626,21 +25651,41 @@ CVE-2024-27844 (The issue was addressed with improved checks. This issue is fixe
 CVE-2024-27840 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2024-27838 (The issue was addressed by adding additional logic. This issue is fixe ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.3-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.3-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27836 (The issue was addressed with improved checks. This issue is fixed in v ...)
 	NOT-FOR-US: Apple
 CVE-2024-27833 (An integer overflow was addressed with improved input validation. This ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.2-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.2-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27832 (The issue was addressed with improved checks. This issue is fixed in t ...)
 	NOT-FOR-US: Apple
 CVE-2024-27831 (An out-of-bounds write issue was addressed with improved input validat ...)
 	NOT-FOR-US: Apple
 CVE-2024-27830 (This issue was addressed through improved state management. This issue ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.3-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.3-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27828 (The issue was addressed with improved memory handling. This issue is f ...)
 	NOT-FOR-US: Apple
 CVE-2024-27820 (The issue was addressed with improved memory handling. This issue is f ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.2-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.2-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27819 (The issue was addressed by restricting options offered on a locked dev ...)
 	NOT-FOR-US: Apple
 CVE-2024-27817 (The issue was addressed with improved checks. This issue is fixed in m ...)
@@ -25654,7 +25699,12 @@ CVE-2024-27812 (The issue was addressed with improvements to the file handling p
 CVE-2024-27811 (The issue was addressed with improved checks. This issue is fixed in t ...)
 	NOT-FOR-US: Apple
 CVE-2024-27808 (The issue was addressed with improved memory handling. This issue is f ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.44.2-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.44.2-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-27807 (The issue was addressed with improved checks. This issue is fixed in i ...)
 	NOT-FOR-US: Apple
 CVE-2024-27806 (This issue was addressed with improved environment sanitization. This  ...)
@@ -43294,7 +43344,12 @@ CVE-2024-27537
 CVE-2024-27536
 	REJECTED
 CVE-2024-23271 (A logic issue was addressed with improved checks. This issue is fixed  ...)
-	NOT-FOR-US: Apple
+	- webkit2gtk 2.42.5-1
+	[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
+	- wpewebkit 2.42.5-1
+	[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
+	[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
+	NOTE: https://webkitgtk.org/security/WSA-2024-0005.html
 CVE-2024-23228 (This issue was addressed through improved state management. This issue ...)
 	NOT-FOR-US: Apple
 CVE-2024-20359 (A vulnerability in a legacy capability that allowed for the preloading ...)


=====================================
data/DSA/list
=====================================
@@ -35,7 +35,7 @@
 	{CVE-2024-23346}
 	[bookworm] - pymatgen 2022.11.7+dfsg1-11+deb12u1
 [30 Aug 2024] DSA-5762-1 webkit2gtk - security update
-	{CVE-2024-4558 CVE-2024-40776 CVE-2024-40779 CVE-2024-40780 CVE-2024-40782 CVE-2024-40785 CVE-2024-40789 CVE-2024-40794}
+	{CVE-2024-4558 CVE-2024-40776 CVE-2024-40779 CVE-2024-40780 CVE-2024-40782 CVE-2024-40785 CVE-2024-40789 CVE-2024-40794 CVE-2024-27830 CVE-2024-27838 CVE-2024-27851}
 	[bookworm] - webkit2gtk 2.44.3-1~deb12u1
 [29 Aug 2024] DSA-5761-1 chromium - security update
 	{CVE-2024-7969 CVE-2024-8193 CVE-2024-8194 CVE-2024-8198}
@@ -268,7 +268,7 @@
 	{CVE-2024-5157 CVE-2024-5158 CVE-2024-5159 CVE-2024-5160}
 	[bookworm] - chromium 125.0.6422.76-1~deb12u1
 [22 May 2024] DSA-5695-1 webkit2gtk - security update
-	{CVE-2024-27834}
+	{CVE-2024-27834 CVE-2024-27808 CVE-2024-27820 CVE-2024-27833 CVE-2024-27850}
 	[bullseye] - webkit2gtk 2.44.2-1~deb11u1
 	[bookworm] - webkit2gtk 2.44.2-1~deb12u1
 [17 May 2024] DSA-5694-1 chromium - security update
@@ -549,7 +549,7 @@
 	[bullseye] - libgit2 1.1.0+dfsg.1-4+deb11u2
 	[bookworm] - libgit2 1.5.1+ds-1+deb12u1
 [08 Feb 2024] DSA-5618-1 webkit2gtk - security update
-	{CVE-2024-23206 CVE-2024-23213 CVE-2024-23222}
+	{CVE-2024-23206 CVE-2024-23213 CVE-2024-23222 CVE-2024-23271}
 	[bullseye] - webkit2gtk 2.42.5-1~deb11u1
 	[bookworm] - webkit2gtk 2.42.5-1~deb12u1
 [08 Feb 2024] DSA-5617-1 chromium - security update


=====================================
data/dsa-needed.txt
=====================================
@@ -50,6 +50,8 @@ tryton-server (jmm)
 --
 twisted (jmm)
 --
+webkit2gtk (berto)
+--
 xen
 --
 zabbix



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/887b1501e1de19ff2e41a5424a9c8948fcec2c30

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/887b1501e1de19ff2e41a5424a9c8948fcec2c30
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240926/2bce34c3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list