ALT-BU-2017-3143-1
Branch sisyphus update bulletin.
Package libwebkitgtk4 updated to version 2.16.3-alt1 for branch sisyphus in task 183446.
Closed vulnerabilities
BDU:2018-00197
Уязвимость функции IPC::Connection::processMessage UNIX IPC ядра отображения веб-страниц WebKitGTK+, позволяющая нарушителю вызвать переполнение буфера
Modified: 2024-11-21
CVE-2017-1000121
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products.
Modified: 2024-11-21
CVE-2017-1000122
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secondary process to cause a denial of service (release assertion) of the UI process. This vulnerability does not affect Apple products.
Modified: 2024-11-21
CVE-2017-2350
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Modified: 2024-11-21
CVE-2017-2354
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 95736
- 95736
- 1037668
- 1037668
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207481
- https://support.apple.com/HT207481
- https://support.apple.com/HT207482
- https://support.apple.com/HT207482
- https://support.apple.com/HT207484
- https://support.apple.com/HT207484
- https://support.apple.com/HT207485
- https://support.apple.com/HT207485
- https://support.apple.com/HT207486
- https://support.apple.com/HT207486
Modified: 2024-11-21
CVE-2017-2355
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access and application crash) via a crafted web site.
- 95736
- 95736
- 1037668
- 1037668
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207481
- https://support.apple.com/HT207481
- https://support.apple.com/HT207482
- https://support.apple.com/HT207482
- https://support.apple.com/HT207484
- https://support.apple.com/HT207484
- https://support.apple.com/HT207485
- https://support.apple.com/HT207485
- https://support.apple.com/HT207486
- https://support.apple.com/HT207486
Modified: 2024-11-21
CVE-2017-2356
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
- 95736
- 95736
- 1037668
- 1037668
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207481
- https://support.apple.com/HT207481
- https://support.apple.com/HT207482
- https://support.apple.com/HT207482
- https://support.apple.com/HT207484
- https://support.apple.com/HT207484
- https://support.apple.com/HT207485
- https://support.apple.com/HT207485
- https://support.apple.com/HT207486
- https://support.apple.com/HT207486
Modified: 2024-11-21
CVE-2017-2360
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
- 95729
- 95729
- 95731
- 95731
- 1037668
- 1037668
- https://support.apple.com/HT207482
- https://support.apple.com/HT207482
- https://support.apple.com/HT207483
- https://support.apple.com/HT207483
- https://support.apple.com/HT207485
- https://support.apple.com/HT207485
- https://support.apple.com/HT207487
- https://support.apple.com/HT207487
- 41165
- 41165
Modified: 2024-11-21
CVE-2017-2363
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
- 95728
- 95728
- 1037668
- 1037668
- GLSA-201706-15
- GLSA-201706-15
- https://support.apple.com/HT207482
- https://support.apple.com/HT207482
- https://support.apple.com/HT207484
- https://support.apple.com/HT207484
- https://support.apple.com/HT207485
- https://support.apple.com/HT207485
- https://support.apple.com/HT207487
- https://support.apple.com/HT207487
- 41449
- 41449
Modified: 2024-11-21
CVE-2017-2365
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site.
Modified: 2024-11-21
CVE-2017-2369
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Modified: 2024-11-21
CVE-2017-2373
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Modified: 2024-11-21
CVE-2017-2496
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
Modified: 2024-11-21
CVE-2017-2510
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.
Modified: 2024-11-21
CVE-2017-2539
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.