Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.4.2025.0735.1
Categoría:SuSE Local Security Checks
Título:SUSE: Security Advisory (SUSE-SU-2025:0735-1)
Resumen:The remote host is missing an update for the 'webkit2gtk3' package(s) announced via the SUSE-SU-2025:0735-1 advisory.
Descripción:Summary:
The remote host is missing an update for the 'webkit2gtk3' package(s) announced via the SUSE-SU-2025:0735-1 advisory.

Vulnerability Insight:
This update for webkit2gtk3 fixes the following issues:

Update to version 2.46.6 (bsc#1236946, bsc#1234851):

- CVE-2025-24143: A maliciously crafted webpage may be able to fingerprint the user.
- CVE-2025-24150: Copying a URL from Web Inspector may lead to command injection.
- CVE-2025-24158: Processing web content may lead to a denial-of-service.
- CVE-2025-24162: Processing maliciously crafted web content may lead to an unexpected process crash.
- CVE-2024-54479: Processing maliciously crafted web content may lead to an unexpected process crash.
- CVE-2024-54502: Processing maliciously crafted web content may lead to an unexpected process crash.
- CVE-2024-54505: Processing maliciously crafted web content may lead to memory corruption.
- CVE-2024-54508: Processing maliciously crafted web content may lead to an unexpected process crash.
- CVE-2024-54543: Processing maliciously crafted web content may lead to memory corruption.

Already fixed in previous releases:

- CVE-2024-27856: Processing a file may lead to unexpected app termination or arbitrary code execution.
- CVE-2024-54534: Processing maliciously crafted web content may lead to memory corruption.
- CVE-2024-54658: Processing web content may lead to a denial-of-service.

Affected Software/OS:
'webkit2gtk3' package(s) on SUSE Linux Enterprise Server 15-SP3, SUSE Linux Enterprise Server for SAP Applications 15-SP3.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2024-27856
Common Vulnerability Exposure (CVE) ID: CVE-2024-54479
Common Vulnerability Exposure (CVE) ID: CVE-2024-54502
Common Vulnerability Exposure (CVE) ID: CVE-2024-54505
Common Vulnerability Exposure (CVE) ID: CVE-2024-54508
Common Vulnerability Exposure (CVE) ID: CVE-2024-54534
Common Vulnerability Exposure (CVE) ID: CVE-2024-54543
Common Vulnerability Exposure (CVE) ID: CVE-2024-54658
Common Vulnerability Exposure (CVE) ID: CVE-2025-24143
Common Vulnerability Exposure (CVE) ID: CVE-2025-24150
Common Vulnerability Exposure (CVE) ID: CVE-2025-24158
Common Vulnerability Exposure (CVE) ID: CVE-2025-24162
CopyrightCopyright (C) 2025 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.