QID 174960

QID 174960: SUSE Enterprise Linux Security Update for webkit2gtk3 (SUSE-SU-2021:1430-1)

This update for webkit2gtk3 fixes the following issues:

- Update to version 2.32.0 (bsc#1184155):
* Fix the authentication request port when URL omits the port.
* Fix iframe scrolling when main frame is scrolled in async
* scrolling mode.
* Stop using g_memdup.
* Show a warning message when overriding signal handler for
* threading suspension.
* Fix the build on RISC-V with GCC 11.
* Fix several crashes and rendering issues.
* Security fixes: CVE-2021-1788, CVE-2021-1844, CVE-2021-1871
- Update in version 2.30.6 (bsc#1184262):
* Update user agent quirks again for Google Docs and Google Drive.
* Fix several crashes and rendering issues.
* Security fixes: CVE-2020-27918, CVE-2020-29623, CVE-2021-1765
CVE-2021-1789, CVE-2021-1799, CVE-2021-1801, CVE-2021-1870.
- Update _constraints for armv6/armv7 (bsc#1182719)
- restore NPAPI plugin support which was removed in 2.32.0

Successful exploitation allows attacker to compromise the system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest package which contains the patch. To install this SUSE Security, Update use YaST online_update. Alternatively you can run the command listed for your product. To install packages using the command line interface, use command "yum update". Refer to Suse security advisory: SUSE-SU-2021:1430-1 to address this issue and obtain further details.
    Software Advisories
    Advisory ID Software Component Link
    SUSE-SU-2021:1430-1 SUSE Enterprise Linux URL Logo lists.suse.com/pipermail/sle-security-updates/2021-April/008699.html