{"schema_version":"1.7.3","id":"SUSE-SU-2024:1293-1","published":"2024-04-15T14:48:15Z","modified":"2026-02-04T02:29:44.646573Z","related":["CVE-2023-42843","CVE-2023-42950","CVE-2023-42956","CVE-2024-23252","CVE-2024-23254","CVE-2024-23263","CVE-2024-23280","CVE-2024-23284"],"upstream":["CVE-2023-42843","CVE-2023-42950","CVE-2023-42956","CVE-2024-23252","CVE-2024-23254","CVE-2024-23263","CVE-2024-23280","CVE-2024-23284"],"summary":"Security update for webkit2gtk3","details":"\nwebkit2gtk3 was updated to fix the following issues:\n\nUpdate to version 2.44.0 (boo#1222010):\n\n- CVE-2024-23252:\n\n    Credit to anbu1024 of SecANT.\n    Impact: Processing web content may lead to a denial-of-service.\n    Description: The issue was addressed with improved memory handling.\n\n- CVE-2024-23254:\n\n    Credit to James Lee (@Windowsrcer).\n    Impact: A malicious website may exfiltrate audio data cross-origin.\n    Description: The issue was addressed with improved UI handling.\n\n- CVE-2024-23263:\n\n    Credit to Johan Carlsson (joaxcar).\n    Impact: Processing maliciously crafted web content may prevent\n    Content Security Policy from being enforced. Description: A logic\n    issue was addressed with improved validation.\n\n- CVE-2024-23280:\n\n    Credit to An anonymous researcher.\n    Impact: A maliciously crafted webpage may be able to fingerprint the\n    user. Description: An injection issue was addressed with improved\n    validation.\n\n- CVE-2024-23284:\n\n    Credit to Georg Felber and Marco Squarcina.\n    Impact: Processing maliciously crafted web content may prevent\n    Content Security Policy from being enforced. Description: A logic\n    issue was addressed with improved state management.\n\n- CVE-2023-42950:\n\n    Credit to Nan Wang (@eternalsakura13) of 360 Vulnerability Research\n    Institute and rushikesh nandedkar.\n    Impact: Processing maliciously crafted web content may lead to\n    arbitrary code execution. Description: A use after free issue was\n    addressed with improved memory management.\n\n- CVE-2023-42956:\n\n    Credit to SungKwon Lee (Demon.Team).\n    Impact: Processing web content may lead to a denial-of-service.\n    Description: The issue was addressed with improved memory handling.\n\n- CVE-2023-42843:\n\n    Credit to Kacper Kwapisz (@KKKas_).\n    Impact: Visiting a malicious website may lead to address bar\n    spoofing. Description: An inconsistent user interface issue was\n    addressed with improved state management.\n\n\n+ Make the DOM accessibility tree reachable from UI process with GTK4.\n+ Removed the X11 and WPE renderers in favor of DMA-BUF.\n+ Improved vblank synchronization when rendering.\n+ Removed key event reinjection in GTK4 to make keyboard shortcuts work in web sites.\n+ Fix gamepads detection by correctly handling focused window in GTK4.\n\n- Use WebAssembly on aarch64. It is the upstream default and no\n  longer makes the build fail. Stop passing -DENABLE_C_LOOP=ON,\n  -DENABLE_WEBASSEMBLY=OFF and -DENABLE_SAMPLING_PROFILER=OFF for\n  the same reason.\n","affected":[{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.44.0-4.3.2"}]}],"ecosystem_specific":{"binaries":[{"typelib-1_0-WebKit2WebExtension-4_0":"2.44.0-4.3.2","webkit2gtk3-devel":"2.44.0-4.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:1293-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.44.0-4.3.2"}]}],"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.44.0-4.3.2","libwebkit2gtk-4_0-37":"2.44.0-4.3.2","libwebkit2gtk3-lang":"2.44.0-4.3.2","typelib-1_0-JavaScriptCore-4_0":"2.44.0-4.3.2","typelib-1_0-WebKit2-4_0":"2.44.0-4.3.2","typelib-1_0-WebKit2WebExtension-4_0":"2.44.0-4.3.2","webkit2gtk-4_0-injected-bundles":"2.44.0-4.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:1293-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.44.0-4.3.2"}]}],"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.44.0-4.3.2","libwebkit2gtk-4_0-37":"2.44.0-4.3.2","libwebkit2gtk3-lang":"2.44.0-4.3.2","typelib-1_0-JavaScriptCore-4_0":"2.44.0-4.3.2","typelib-1_0-WebKit2-4_0":"2.44.0-4.3.2","typelib-1_0-WebKit2WebExtension-4_0":"2.44.0-4.3.2","webkit2gtk-4_0-injected-bundles":"2.44.0-4.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:1293-1.json"}},{"package":{"name":"webkit2gtk3","ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP5","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.44.0-4.3.2"}]}],"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18-32bit":"2.44.0-4.3.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:1293-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20241293-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1222010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42950"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-42956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23263"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23280"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-23284"}]}