Description: | Summary: The remote host is missing an update for the 'webkit2gtk3' package(s) announced via the openSUSE-SU-2021:0637-1 advisory.
Vulnerability Insight: This update for webkit2gtk3 fixes the following issues:
- Update to version 2.32.0 (bsc#1184155):
* Fix the authentication request port when URL omits the port.
* Fix iframe scrolling when main frame is scrolled in async
* scrolling mode.
* Stop using g_memdup.
* Show a warning message when overriding signal handler for
* threading suspension.
* Fix the build on RISC-V with GCC 11.
* Fix several crashes and rendering issues.
* Security fixes: CVE-2021-1788, CVE-2021-1844, CVE-2021-1871
- Update in version 2.30.6 (bsc#1184262):
* Update user agent quirks again for Google Docs and Google Drive.
* Fix several crashes and rendering issues.
* Security fixes: CVE-2020-27918, CVE-2020-29623, CVE-2021-1765 CVE-2021-1789, CVE-2021-1799, CVE-2021-1801, CVE-2021-1870.
- Update _constraints for armv6/armv7 (bsc#1182719)
- restore NPAPI plugin support which was removed in 2.32.0
This update was imported from the SUSE:SLE-15-SP2:Update update project.
Affected Software/OS: 'webkit2gtk3' package(s) on openSUSE Leap 15.2.
Solution: Please install the updated package(s).
CVSS Score: 7.5
CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
|