{"schema_version":"1.7.3","id":"openSUSE-SU-2019:0308-1","published":"2019-03-23T11:09:58Z","modified":"2026-02-04T04:04:29.940507Z","related":["CVE-2018-4437","CVE-2018-4438","CVE-2018-4441","CVE-2018-4442","CVE-2018-4443","CVE-2018-4464","CVE-2019-6212","CVE-2019-6215","CVE-2019-6216","CVE-2019-6217","CVE-2019-6226","CVE-2019-6227","CVE-2019-6229","CVE-2019-6233","CVE-2019-6234"],"upstream":["CVE-2018-4437","CVE-2018-4438","CVE-2018-4441","CVE-2018-4442","CVE-2018-4443","CVE-2018-4464","CVE-2019-6212","CVE-2019-6215","CVE-2019-6216","CVE-2019-6217","CVE-2019-6226","CVE-2019-6227","CVE-2019-6229","CVE-2019-6233","CVE-2019-6234"],"summary":"Security update for webkit2gtk3","details":"This update for webkit2gtk3 to version 2.22.6 fixes the following issues (boo#1124937 boo#1119558):\n\nSecurity vulnerabilities fixed:\n\n- CVE-2018-4437: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling. (boo#1119553)\n- CVE-2018-4438: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A logic issue existed resulting in memory\n  corruption. This was addressed with improved state management. (boo#1119554)\n- CVE-2018-4441: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119555)\n- CVE-2018-4442: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119556)\n- CVE-2018-4443: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling. (boo#1119557)\n- CVE-2018-4464: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling. (boo#1119558)\n- CVE-2019-6212: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6215: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A type confusion issue was addressed with improved\n  memory handling.\n- CVE-2019-6216: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6217: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6226: Processing maliciously crafted web content may lead to\n  arbitrary code execution. Multiple memory corruption issues were addressed\n  with improved memory handling.\n- CVE-2019-6227: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n- CVE-2019-6229: Processing maliciously crafted web content may lead to\n  universal cross site scripting. A logic issue was addressed with improved\n  validation.\n- CVE-2019-6233: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n- CVE-2019-6234: Processing maliciously crafted web content may lead to\n  arbitrary code execution. A memory corruption issue was addressed with\n  improved memory handling.\n\nOther bug fixes and changes:\n\n- Make kinetic scrolling slow down smoothly when reaching the ends of pages,\n  instead of abruptly, to better match the GTK+ behaviour.\n- Fix Web inspector magnifier under Wayland.\n- Fix garbled rendering of some websites (e.g. YouTube) while scrolling under\n  X11.\n- Fix several crashes, race conditions, and rendering issues.\n\nFor a detailed list of changes, please refer to:\n\n- https://webkitgtk.org/security/WSA-2019-0001.html\n- https://webkitgtk.org/2019/02/09/webkitgtk2.22.6-released.html\n- https://webkitgtk.org/security/WSA-2018-0009.html\n- https://webkitgtk.org/2018/12/13/webkitgtk2.22.5-released.html\n\n    \nThis update was imported from the SUSE:SLE-15:Update update project.","affected":[{"package":{"name":"webkit2gtk3","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.22.6-lp150.2.12.1"}]}],"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.22.6-lp150.2.12.1","libjavascriptcoregtk-4_0-18-32bit":"2.22.6-lp150.2.12.1","libwebkit2gtk-4_0-37":"2.22.6-lp150.2.12.1","libwebkit2gtk-4_0-37-32bit":"2.22.6-lp150.2.12.1","libwebkit2gtk3-lang":"2.22.6-lp150.2.12.1","typelib-1_0-JavaScriptCore-4_0":"2.22.6-lp150.2.12.1","typelib-1_0-WebKit2-4_0":"2.22.6-lp150.2.12.1","typelib-1_0-WebKit2WebExtension-4_0":"2.22.6-lp150.2.12.1","webkit-jsc-4":"2.22.6-lp150.2.12.1","webkit2gtk-4_0-injected-bundles":"2.22.6-lp150.2.12.1","webkit2gtk3-devel":"2.22.6-lp150.2.12.1","webkit2gtk3-minibrowser":"2.22.6-lp150.2.12.1","webkit2gtk3-plugin-process-gtk2":"2.22.6-lp150.2.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:0308-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VOC7EROFYXM7H5YCNM5NI27KEAEP5HCQ/#VOC7EROFYXM7H5YCNM5NI27KEAEP5HCQ"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119553"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119556"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119557"},{"type":"REPORT","url":"https://bugzilla.suse.com/1119558"},{"type":"REPORT","url":"https://bugzilla.suse.com/1124937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4441"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4443"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-4464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6212"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6215"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6226"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6233"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-6234"}]}