Bug 28671 - webkit2 security issues fixed upstream (WSA-2021-0002 and WSA-2021-0003)
Summary: webkit2 security issues fixed upstream (WSA-2021-0002 and WSA-2021-0003)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7TOO MGA7-64-OK MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-03-29 08:51 CEST by Nicolas Salguero
Modified: 2021-04-12 22:02 CEST (History)
5 users (show)

See Also:
Source RPM: webkit2-2.30.5-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description Nicolas Salguero 2021-03-29 08:51:56 CEST
Upstream has issued an advisory on March 22:
https://webkitgtk.org/security/WSA-2021-0002.html

See also:
https://webkitgtk.org/2021/03/18/webkitgtk2.30.6-released.html
Nicolas Salguero 2021-03-29 08:53:16 CEST

Whiteboard: (none) => MGA7TOO
Source RPM: (none) => webkit2-2.30.5-1.mga8.src.rpm

Comment 1 Nicolas Salguero 2021-03-29 11:18:12 CEST
Suggested advisory:
========================

Updated webkit2 packages fix security vulnerabilities:

The webkit2 package has been updated to version 2.30.6, fixing several security issues and other bugs.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27918
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29623
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9947
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1765
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1789
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1799
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1801
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1870
https://webkitgtk.org/security/WSA-2021-0002.html
https://webkitgtk.org/2021/03/18/webkitgtk2.30.6-released.html
========================

Updated packages in 7/core/updates_testing:
========================
webkit2-2.30.6-1.mga7
webkit2-jsc-2.30.6-1.mga7
lib(64)webkit2gtk4.0_37-2.30.6-1.mga7
lib(64)javascriptcoregtk4.0_18-2.30.6-1.mga7
lib(64)webkit2-devel-2.30.6-1.mga7
lib(64)javascriptcore-gir4.0-2.30.6-1.mga7
lib(64)webkit2gtk-gir4.0-2.30.6-1.mga7

from SRPM:
webkit2-2.30.6-1.mga7.src.rpm

Updated packages in 8/core/updates_testing:
========================
webkit2-2.30.6-1.mga8
webkit2-jsc-2.30.6-1.mga8
lib(64)webkit2gtk4.0_37-2.30.6-1.mga8
lib(64)javascriptcoregtk4.0_18-2.30.6-1.mga8
lib(64)webkit2-devel-2.30.6-1.mga8
lib(64)javascriptcore-gir4.0-2.30.6-1.mga8
lib(64)webkit2gtk-gir4.0-2.30.6-1.mga8

from SRPM:
webkit2-2.30.6-1.mga8.src.rpm

Status: NEW => ASSIGNED
Assignee: bugsquad => qa-bugs

Comment 2 Nicolas Salguero 2021-03-30 08:16:37 CEST
Upstream has issued an advisory on March 29:
https://webkitgtk.org/security/WSA-2021-0003.html

See also:
https://webkitgtk.org/2021/03/26/webkitgtk2.32.0-released.html

Assignee: qa-bugs => nicolas.salguero
Summary: webkit2 security issues fixed upstream (WSA-2021-0002) => webkit2 security issues fixed upstream (WSA-2021-0002 and WSA-2021-0003)

Comment 3 Nicolas Salguero 2021-03-30 11:00:29 CEST
Suggested advisory:
========================

Updated webkit2 packages fix security vulnerabilities:

The webkit2 package has been updated to version 2.32.0, fixing several security issues and other bugs.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27918
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29623
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9947
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1765
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1789
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1799
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1801
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1870
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1788
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1844
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1871
https://webkitgtk.org/security/WSA-2021-0002.html
https://webkitgtk.org/security/WSA-2021-0003.html
https://webkitgtk.org/2021/03/18/webkitgtk2.30.6-released.html
https://webkitgtk.org/2021/03/26/webkitgtk2.32.0-released.html
========================

Updated packages in 7/core/updates_testing:
========================
webkit2-2.32.0-1.mga7
webkit2-jsc-2.32.0-1.mga7
lib(64)webkit2gtk4.0_37-2.32.0-1.mga7
lib(64)javascriptcoregtk4.0_18-2.32.0-1.mga7
lib(64)webkit2-devel-2.32.0-1.mga7
lib(64)javascriptcore-gir4.0-2.32.0-1.mga7
lib(64)webkit2gtk-gir4.0-2.32.0-1.mga7

from SRPM:
webkit2-2.32.0-1.mga7.src.rpm

Updated packages in 8/core/updates_testing:
========================
webkit2-2.32.0-1.mga8
webkit2-jsc-2.32.0-1.mga8
lib(64)webkit2gtk4.0_37-2.32.0-1.mga8
lib(64)javascriptcoregtk4.0_18-2.32.0-1.mga8
lib(64)webkit2-devel-2.32.0-1.mga8
lib(64)javascriptcore-gir4.0-2.32.0-1.mga8
lib(64)webkit2gtk-gir4.0-2.32.0-1.mga8

from SRPM:
webkit2-2.32.0-1.mga8.src.rpm

Assignee: nicolas.salguero => qa-bugs

Comment 4 Aurelien Oudelet 2021-03-30 17:25:28 CEST
MGA8 x86_64 Plasma.

Updating is OK.
No regression.
MCC help runs fine.

Same on Mageia 7.

CC: (none) => ouaurelien

Comment 5 Herman Viaene 2021-04-02 12:03:12 CEST
MGA7-64 MATE on Peaq C1011
At installation, all packages install OK, except
urpmi lib64webkit2-devel-2.32.0-1.mga7
The following packages can't be installed because they depend on packages
that are older than the installed ones:
lib64mount-devel-2.33.2-1.mga7
lib64glib2.0-devel-2.60.2-1.4.mga7
lib64webkit2-devel-2.32.0-1.mga7

Continuing test:
as per bug 28370
$ zenity  --calendar
13/04/21
[tester7@mach7 ~]$ zenity  --calendar
21/04/21
The first one is by pressing OK on the dialogue, the second one by double clicking on the date cheosen.
OK for me.

CC: (none) => herman.viaene
Whiteboard: MGA7TOO => MGA7TOO MGA7-64-OK

Comment 6 David Walser 2021-04-02 17:18:05 CEST
Since you've already installed glib2.0 and libmount from updates_testing, you need to include those devel packages if you're using QARepo.

CC: (none) => luigiwalser

Comment 7 Thomas Andrews 2021-04-07 02:45:12 CEST
Using the tests in Comment 4 to give the mga8 OK, and Comment 6 explains the issues from Comment 5.

Validating. Advisory in Comment 3.

Keywords: (none) => validated_update
Whiteboard: MGA7TOO MGA7-64-OK => MGA7TOO MGA7-64-OK MGA8-64-OK
CC: (none) => andrewsfarm, sysadmin-bugs

Aurelien Oudelet 2021-04-12 16:15:27 CEST

Keywords: (none) => advisory

Comment 8 Mageia Robot 2021-04-12 22:02:25 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0181.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.