View | Details | Raw Unified | Return to bug 247892
Collapse All | Expand All

(-)vuln.xml (+42 lines)
Line 60 Link Here
61
  <vuln vid="efd03116-c2a9-11ea-82bc-b42e99a1b9c3">
62
    <topic>webkit2-gtk3 -- multible vulnerabilities</topic>
63
    <affects>
64
      <package>
65
	<name>webkit2-gtk3</name>
66
	<range><lt>2.28.3</lt></range>
67
      </package>
68
    </affects>
69
    <description>
70
      <body xmlns="http://www.w3.org/1999/xhtml">
71
	<p>The WebKitGTK project reports vulnerabilities:</p>
72
	<blockquote cite="https://webkitgtk.org/security/WSA-2020-0006.html">
73
	  <ul>
74
      <li>CVE-2020-9802: Processing maliciously crafted web content may lead to arbitrary code execution.</li>
75
      <li>CVE-2020-9803: Processing maliciously crafted web content may lead to arbitrary code execution.</li>
76
      <li>CVE-2020-9805: Processing maliciously crafted web content may lead to universal cross site scripting.</li>
77
      <li>CVE-2020-9806: Processing maliciously crafted web content may lead to arbitrary code execution.</li>
78
      <li>CVE-2020-9807: Processing maliciously crafted web content may lead to arbitrary code execution.</li>
79
      <li>CVE-2020-9843: Processing maliciously crafted web content may lead to a cross site scripting attack.</li>
80
      <li>CVE-2020-9850: A remote attacker may be able to cause arbitrary code execution.</li>
81
      <li>CVE-2020-13753: CLONE_NEWUSER could potentially be used to confuse xdg- desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal’s input buffer.</li>
82
      </ul>
83
	</blockquote>
84
      </body>
85
    </description>
86
    <references>
87
      <url>https://webkitgtk.org/security/WSA-2020-0006.html</url>
88
      <cvename>CVE-2020-9802</cvename>
89
      <cvename>CVE-2020-9803</cvename>
90
      <cvename>CVE-2020-9805</cvename>
91
      <cvename>CVE-2020-9806</cvename>
92
      <cvename>CVE-2020-9807</cvename>
93
      <cvename>CVE-2020-9843</cvename>
94
      <cvename>CVE-2020-9850</cvename>
95
      <cvename>CVE-2020-13753</cvename>
96
    </references>
97
    <dates>
98
      <discovery>2020-07-10</discovery>
99
      <entry>2020-07-10</entry>
100
    </dates>
101
  </vuln>
102

Return to bug 247892