Vulnerability   
Search   
    Search 187964 CVE descriptions
and 85075 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.704681
Category:Debian Local Security Checks
Title:Debian: Security Advisory for webkit2gtk (DSA-4681-1)
Summary:The remote host is missing an update for the 'webkit2gtk'; package(s) announced via the DSA-4681-1 advisory.
Description:Summary:
The remote host is missing an update for the 'webkit2gtk'
package(s) announced via the DSA-4681-1 advisory.

Vulnerability Insight:
The following vulnerability has been discovered in the webkit2gtk web
engine:

CVE-2020-3885
Ryan Pickren discovered that a file URL may be incorrectly
processed.

CVE-2020-3894
Sergei Glazunov discovered that a race condition may allow an
application to read restricted memory.

CVE-2020-3895
grigoritchy discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2020-3897
Brendan Draper discovered that a remote attacker may be able to
cause arbitrary code execution.

CVE-2020-3899
OSS-Fuzz discovered that a remote attacker may be able to cause
arbitrary code execution.

CVE-2020-3900
Dongzhuo Zhao discovered that processing maliciously crafted web
content may lead to arbitrary code execution.

CVE-2020-3901
Benjamin Randazzo discovered that processing maliciously crafted
web content may lead to arbitrary code execution.

CVE-2020-3902
Yigit Can Yilmaz discovered that processing maliciously crafted
web content may lead to a cross site scripting attack.

Affected Software/OS:
'webkit2gtk' package(s) on Debian Linux.

Solution:
For the stable distribution (buster), these problems have been fixed in
version 2.28.2-2~
deb10u1.

We recommend that you upgrade your webkit2gtk packages.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-3885
Debian Security Information: DSA-4681 (Google Search)
https://www.debian.org/security/2020/dsa-4681
https://security.gentoo.org/glsa/202006-08
https://support.apple.com/HT211101
https://support.apple.com/HT211102
https://support.apple.com/HT211104
https://support.apple.com/HT211105
https://support.apple.com/HT211106
https://support.apple.com/HT211107
http://www.openwall.com/lists/oss-security/2020/04/27/3
Common Vulnerability Exposure (CVE) ID: CVE-2020-3894
http://packetstormsecurity.com/files/157378/WebKit-AudioArray-allocate-Data-Race-Out-Of-Bounds-Access.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-3895
https://support.apple.com/HT211103
Common Vulnerability Exposure (CVE) ID: CVE-2020-3897
Common Vulnerability Exposure (CVE) ID: CVE-2020-3899
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4V2TWGEZTYFWE5HIORULXJAUDJ4NXII/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPGNJ7JQCD6IE2SCSFAIMSUY5XHOYWKE/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SYLI3NEKPO5FTXFOBKRSRQLHCTZOTHCZ/
SuSE Security Announcement: openSUSE-SU-2020:0646 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00015.html
https://usn.ubuntu.com/4347-1/
Common Vulnerability Exposure (CVE) ID: CVE-2020-3900
Common Vulnerability Exposure (CVE) ID: CVE-2020-3901
Common Vulnerability Exposure (CVE) ID: CVE-2020-3902
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 85075 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.