FreeBSD Bugzilla – Attachment 216361 Details for
Bug 247892
www/webkit2-gtk3: Multiple Vulnerabilities
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
patch for vuxml to inform users
webkit.diff (text/plain), 2.15 KB, created by
rob2g2
on 2020-07-10 12:50:32 UTC
(
hide
)
Description:
patch for vuxml to inform users
Filename:
MIME Type:
Creator:
rob2g2
Created:
2020-07-10 12:50:32 UTC
Size:
2.15 KB
patch
obsolete
>--- vuln2.xml Fri Jul 10 14:36:07 2020 >+++ vuln.xml Fri Jul 10 14:47:46 2020 >@@ -60,0 +61,42 @@ >+ <vuln vid="efd03116-c2a9-11ea-82bc-b42e99a1b9c3"> >+ <topic>webkit2-gtk3 -- multible vulnerabilities</topic> >+ <affects> >+ <package> >+ <name>webkit2-gtk3</name> >+ <range><lt>2.28.3</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>The WebKitGTK project reports vulnerabilities:</p> >+ <blockquote cite="https://webkitgtk.org/security/WSA-2020-0006.html"> >+ <ul> >+ <li>CVE-2020-9802: Processing maliciously crafted web content may lead to arbitrary code execution.</li> >+ <li>CVE-2020-9803: Processing maliciously crafted web content may lead to arbitrary code execution.</li> >+ <li>CVE-2020-9805: Processing maliciously crafted web content may lead to universal cross site scripting.</li> >+ <li>CVE-2020-9806: Processing maliciously crafted web content may lead to arbitrary code execution.</li> >+ <li>CVE-2020-9807: Processing maliciously crafted web content may lead to arbitrary code execution.</li> >+ <li>CVE-2020-9843: Processing maliciously crafted web content may lead to a cross site scripting attack.</li> >+ <li>CVE-2020-9850: A remote attacker may be able to cause arbitrary code execution.</li> >+ <li>CVE-2020-13753: CLONE_NEWUSER could potentially be used to confuse xdg- desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminalâs input buffer.</li> >+ </ul> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <url>https://webkitgtk.org/security/WSA-2020-0006.html</url> >+ <cvename>CVE-2020-9802</cvename> >+ <cvename>CVE-2020-9803</cvename> >+ <cvename>CVE-2020-9805</cvename> >+ <cvename>CVE-2020-9806</cvename> >+ <cvename>CVE-2020-9807</cvename> >+ <cvename>CVE-2020-9843</cvename> >+ <cvename>CVE-2020-9850</cvename> >+ <cvename>CVE-2020-13753</cvename> >+ </references> >+ <dates> >+ <discovery>2020-07-10</discovery> >+ <entry>2020-07-10</entry> >+ </dates> >+ </vuln> >+
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 247892
: 216361