Bug 26487 - webkit2 security issue fixed upstream (WSA-2020-0004, CVE-2020-11793)
Summary: webkit2 security issue fixed upstream (WSA-2020-0004, CVE-2020-11793)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-04-16 15:36 CEST by David Walser
Modified: 2020-04-20 16:03 CEST (History)
4 users (show)

See Also:
Source RPM: webkit2-2.28.0-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-04-16 15:36:05 CEST
Upstream has issued an advisory today (April 16):
https://webkitgtk.org/security/WSA-2020-0004.html

The issue is fixed upstream in 2.28.1:
https://webkitgtk.org/2020/04/13/webkitgtk2.28.1-released.html
Comment 1 David Walser 2020-04-16 15:37:27 CEST
Update checked into SVN for Mageia 7 and currently building in Cauldron.
Comment 2 David Walser 2020-04-16 19:00:10 CEST
Suggested advisory:
========================

Updated webkit2 packages fix security vulnerabilities:

The webkit2 package has been updated to version 2.28.1, fixing security issues
and other bugs.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11793
https://webkitgtk.org/2020/04/13/webkitgtk2.28.1-released.html
https://webkitgtk.org/security/WSA-2020-0004.html
========================

Updated packages in core/updates_testing:
========================
webkit2-2.28.1-1.mga7
webkit2-jsc-2.28.1-1.mga7
libwebkit2gtk4.0_37-2.28.1-1.mga7
libjavascriptcoregtk4.0_18-2.28.1-1.mga7
libwebkit2-devel-2.28.1-1.mga7
libjavascriptcore-gir4.0-2.28.1-1.mga7
libwebkit2gtk-gir4.0-2.28.1-1.mga7

from webkit2-2.28.1-1.mga7.src.rpm

Assignee: bugsquad => qa-bugs

Comment 3 Herman Viaene 2020-04-17 14:29:25 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues.
Ref bug 26340 for testing.
$ zenity --calendar
15/04/21
picked 15 April 2021 from displayed calendar and gor correct feedback.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 4 Thomas Andrews 2020-04-17 16:17:58 CEST
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2020-04-20 01:31:10 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2020-04-20 16:03:47 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0177.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.