Bug 31076 - webkit2 security issues fixed upstream (WSA-2022-0010)
Summary: webkit2 security issues fixed upstream (WSA-2022-0010)
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2022-11-04 17:12 CET by David Walser
Modified: 2022-11-13 03:27 CET (History)
5 users (show)

See Also:
Source RPM: webkit2-2.36.8-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-11-04 17:12:29 CET
Upstream has issued an advisory on November 4:
https://webkitgtk.org/security/WSA-2022-0010.html

The issues are fixed upstream in 2.38.2:
https://webkitgtk.org/2022/11/04/webkitgtk2.38.2-released.html
David Walser 2022-11-04 17:12:49 CET

Status comment: (none) => Fixed upstream in 2.38.2
Whiteboard: (none) => MGA8TOO
CC: (none) => nicolas.salguero

Comment 1 Lewis Smith 2022-11-06 19:05:36 CET
NicolasS has already put version 2.38.2 into Cauldron, so please excuse assigning this to you to wrap up.

Assignee: bugsquad => nicolas.salguero
CC: nicolas.salguero => (none)

Comment 2 Nicolas Salguero 2022-11-07 17:00:03 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability and other issues.

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32888
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32923
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42799
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42823
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-42824
https://webkitgtk.org/security/WSA-2022-0010.html
https://webkitgtk.org/2022/11/04/webkitgtk2.38.2-released.html
========================

Updated packages in core/updates_testing:
========================
lib(64)javascriptcoregtk4.0_18-2.38.2-1.mga8
lib(64)javascriptcore-gir4.0-2.38.2-1.mga8
lib(64)webkit2gtk4.0_37-2.38.2-1.mga8
lib(64)webkit2gtk-gir4.0-2.38.2-1.mga8
lib(64)webkit2-devel-2.38.2-1.mga8
webkit2-2.38.2-1.mga8
webkit2-jsc-2.38.2-1.mga8.x86_64.rpm

from SRPM:
webkit2-2.38.2-1.mga8.src.rpm

CC: (none) => nicolas.salguero
Status comment: Fixed upstream in 2.38.2 => (none)
Whiteboard: MGA8TOO => (none)
Version: Cauldron => 8
Status: NEW => ASSIGNED
Assignee: nicolas.salguero => qa-bugs

Comment 3 Herman Viaene 2022-11-11 12:13:18 CET
MGA8-64 MATE on Acer Aspire 5253
No installation issues
Ref bug 30866 for testing
Closed and restarted MCC, rummaged around in its different sections (firewall, local disks, visibilty on SMB shares, Hardware, all works OK.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA8-64-OK

Comment 4 Thomas Andrews 2022-11-12 00:01:27 CET
On Foolishness, my 32-bit Del Inspiron 5100, with a 32-bit Xfce system, there were also no installation issues.

The issue with MCC, in that it comes up with a blank screen, has not been fixed, but there is some progress. 

Previously, the window was completely unresponsive. Now, there are indications that the left hand pane is responding. You can move the cursor over an option, click on it, and it stays highlighted, as if it had moved to the indicated section. The right hand pane stays blank, but as the cursor is moved over it you can see it change over different parts of the blank pane, and if you click on it when you see a pointing hand it brings up the Mageia tool you would expect from that position.

I'm not going to give this a 32-bit OK, as it isn't fixed for that arch yet, but I will validate it because there has been progress and there are no new regressions that I can see.

Advisory in comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2022-11-13 00:25:08 CET

CC: (none) => davidwhodgins
Keywords: (none) => advisory

Comment 5 Mageia Robot 2022-11-13 03:27:02 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2022-0421.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.