Description: | Description: The remote host is missing an update to webkitgtk announced via advisory FEDORA-2011-0121.
Update Information:
- New stable release, API and ABI compatible with previous 1.2.x versions - Fixes crashes with newer libpng (>= 1.4) - The patches to fix the following CVEs are included with help from Huzaifa Sidhpurwala from the Red Hat security team
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-1791 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577
References:
[ 1 ] Bug #656118 - CVE-2010-4198 WebKit: Memory corruption due to improper handling of large text area https://bugzilla.redhat.com/show_bug.cgi?id=656118 [ 2 ] Bug #656115 - CVE-2010-4197 WebKit: Use-after-free vulnerabiity related to text editing causes memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=656115 [ 3 ] Bug #656129 - CVE-2010-4206 WebKit: Array index error during processing of an SVG document https://bugzilla.redhat.com/show_bug.cgi?id=656129 [ 4 ] Bug #667022 - CVE-2010-3812 webkit: Integer overflow in WebKit's handling of Text objects https://bugzilla.redhat.com/show_bug.cgi?id=667022 [ 5 ] Bug #667024 - CVE-2010-3813 webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting https://bugzilla.redhat.com/show_bug.cgi?id=667024 [ 6 ] Bug #667025 - CVE-2010-4577 webkit: CSS Font Face Parsing Type Confusion Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=667025 [ 7 ] Bug #656126 - CVE-2010-4204 WebKit: Use-after-free vulnerability related frame object https://bugzilla.redhat.com/show_bug.cgi?id=656126
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update webkitgtk' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2011-0121
Risk factor : Critical
CVSS Score: 10.0
|