Bug 30680 - webkit2 security issues fixed upstream (WSA-2022-0007)
Summary: webkit2 security issues fixed upstream (WSA-2022-0007)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-07-28 23:23 CEST by David Walser
Modified: 2022-08-20 12:05 CEST (History)
3 users (show)

See Also:
Source RPM: webkit2-2.36.4-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-07-28 23:23:31 CEST
Upstream has issued an advisory today (July 28):
https://webkitgtk.org/security/WSA-2022-0007.html

The issues are fixed upstream in 2.36.5:
https://webkitgtk.org/2022/07/28/webkitgtk2.36.5-released.html
Comment 1 Nicolas Salguero 2022-08-16 13:16:26 CEST
There is a new version 2.36.6:
https://webkitgtk.org/2022/08/07/webkitgtk2.36.6-released.html
Comment 2 Nicolas Salguero 2022-08-16 17:53:13 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities and other issues.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32792
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32816
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2294
https://webkitgtk.org/security/WSA-2022-0007.html
https://webkitgtk.org/2022/07/28/webkitgtk2.36.5-released.html
https://webkitgtk.org/2022/08/07/webkitgtk2.36.6-released.html
========================

Updated packages in core/updates_testing:
========================
lib(64)javascriptcoregtk4.0_18-2.36.6-1.mga8
lib(64)javascriptcore-gir4.0-2.36.6-1.mga8
lib(64)webkit2gtk4.0_37-2.36.6-1.mga8
lib(64)webkit2gtk-gir4.0-2.36.6-1.mga8
lib(64)webkit2-devel-2.36.6-1.mga8
webkit2-2.36.6-1.mga8
webkit2-jsc-2.36.6-1.mga8.x86_64.rpm

from SRPM:
webkit2-2.36.6-1.mga8.src.rpm

CC: (none) => nicolas.salguero
Assignee: nicolas.salguero => qa-bugs
Status: NEW => ASSIGNED

Comment 3 Dave Hodgins 2022-08-20 03:18:15 CEST
Tested using zenity --calendar. Validating the update.

Keywords: (none) => advisory, validated_update
CC: (none) => davidwhodgins, sysadmin-bugs
Whiteboard: (none) => MGA8-64-OK

Comment 4 Mageia Robot 2022-08-20 12:05:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0287.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.