Description: | Description: The remote host is missing an update to webkitgtk announced via advisory FEDORA-2010-15957.
Update Information:
- New stable release, API and ABI compatible with previous 1.2.x versions.
- The patches to fix the following CVEs are included with help from Vincent Danen and other members of the Red Hat security team:
CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259
References:
[ 1 ] Bug #628032 - CVE-2010-3113 webkit: memory corruption when handling SVG documents https://bugzilla.redhat.com/show_bug.cgi?id=628032 [ 2 ] Bug #631946 - CVE-2010-1814 webkit: memory corruption flaw when handling form menus https://bugzilla.redhat.com/show_bug.cgi?id=631946 [ 3 ] Bug #631939 - CVE-2010-1812 webkit: use-after-free flaw in handling of selections https://bugzilla.redhat.com/show_bug.cgi?id=631939 [ 4 ] Bug #631948 - CVE-2010-1815 webkit: use-after-free flaw when handling scrollbars https://bugzilla.redhat.com/show_bug.cgi?id=631948 [ 5 ] Bug #628071 - CVE-2010-3115 webkit: address bar spoofing with history bug https://bugzilla.redhat.com/show_bug.cgi?id=628071 [ 6 ] Bug #627703 - CVE-2010-1807 webkit: input validation error when parsing certain NaN values https://bugzilla.redhat.com/show_bug.cgi?id=627703 [ 7 ] Bug #628035 - CVE-2010-3114 webkit: bad cast with text editing https://bugzilla.redhat.com/show_bug.cgi?id=628035 [ 8 ] Bug #640353 - CVE-2010-3116 webkit: memory corruption with MIME types https://bugzilla.redhat.com/show_bug.cgi?id=640353 [ 9 ] Bug #640357 - CVE-2010-3257 webkit: stale pointer issue with focusing https://bugzilla.redhat.com/show_bug.cgi?id=640357 [ 10 ] Bug #640360 - CVE-2010-3259 webkit: cross-origin image theft https://bugzilla.redhat.com/show_bug.cgi?id=640360
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update webkitgtk' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2010-15957
Risk factor : Critical
CVSS Score: 10.0
|