{"schema_version":"1.7.3","id":"SUSE-SU-2019:0497-1","published":"2019-02-26T15:43:40Z","modified":"2026-02-04T03:29:03.211941Z","related":["CVE-2018-4437","CVE-2018-4438","CVE-2018-4441","CVE-2018-4442","CVE-2018-4443","CVE-2018-4464","CVE-2019-6212","CVE-2019-6215","CVE-2019-6216","CVE-2019-6217","CVE-2019-6226","CVE-2019-6227","CVE-2019-6229","CVE-2019-6233","CVE-2019-6234"],"upstream":["CVE-2018-4437","CVE-2018-4438","CVE-2018-4441","CVE-2018-4442","CVE-2018-4443","CVE-2018-4464","CVE-2019-6212","CVE-2019-6215","CVE-2019-6216","CVE-2019-6217","CVE-2019-6226","CVE-2019-6227","CVE-2019-6229","CVE-2019-6233","CVE-2019-6234"],"summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 to version 2.22.6 fixes the following issues (boo#1124937 boo#1119558):\n\nSecurity vulnerabilities fixed:\n\n- CVE-2018-4437: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling. (boo#1119553)\n- CVE-2018-4438: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A logic issue existed resulting in memory\n  corruption. This was addressed with improved state management. (boo#1119554)\n- CVE-2018-4441: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119555)\n- CVE-2018-4442: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119556)\n- CVE-2018-4443: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119557)\n- CVE-2018-4464: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling. (boo#1119558)\n- CVE-2019-6212: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6215: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A type confusion issue was addressed with improved\n  memory handling.\n- CVE-2019-6216: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6217: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6226: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6227: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n- CVE-2019-6229: Processing maliciously crafted web content may lead to\n  universal cross site scripting. A logic issue was addressed with improved\n  validation.\n- CVE-2019-6233: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n- CVE-2019-6234: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n\nOther bug fixes and changes:\n\n- Make kinetic scrolling slow down smoothly when reaching the ends of pages,\n  instead of abruptly, to better match the GTK+ behaviour.\n- Fix Web inspector magnifier under Wayland.\n- Fix garbled rendering of some websites (e.g. YouTube) while scrolling under\n  X11.\n- Fix several crashes, race conditions, and rendering issues.\n\nFor a detailed list of changes, please refer to:\n\n- https://webkitgtk.org/security/WSA-2019-0001.html\n- https://webkitgtk.org/2019/02/09/webkitgtk2.22.6-released.html\n- https://webkitgtk.org/security/WSA-2018-0009.html\n- https://webkitgtk.org/2018/12/13/webkitgtk2.22.5-released.html\n\n    ","affected":[{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.22.6-3.18.2"}]}],"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.22.6-3.18.2","libwebkit2gtk-4_0-37":"2.22.6-3.18.2","libwebkit2gtk3-lang":"2.22.6-3.18.2","webkit2gtk-4_0-injected-bundles":"2.22.6-3.18.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:0497-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.22.6-3.18.2"}]}],"ecosystem_specific":{"binaries":[{"typelib-1_0-JavaScriptCore-4_0":"2.22.6-3.18.2","typelib-1_0-WebKit2-4_0":"2.22.6-3.18.2","typelib-1_0-WebKit2WebExtension-4_0":"2.22.6-3.18.2","webkit2gtk3-devel":"2.22.6-3.18.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:0497-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2019/suse-su-20190497-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119553"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119556"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119557"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119558"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6233"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6234"}]}