Opened 6 years ago

Closed 6 years ago

Last modified 6 years ago

#9947 closed enhancement (fixed)

webkitgtk-2.18.3

Reported by: bdubbs@… Owned by: Douglas R. Reno
Priority: high Milestone: 8.2
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Douglas R. Reno, 6 years ago

Owner: changed from blfs-book@… to Douglas R. Reno
Status: newassigned

Going to go ahead and take this one

comment:2 by Douglas R. Reno, 6 years ago

Priority: normalhigh
Summary: webkitgtk-2.18.2webkitgtk-2.18.3

Update to 2.18.3

NOTES FROM 2.18.2

What’s new in the WebKitGTK+ 2.18.2 release?
Fix rendering of arabic text.
Fix a crash in the web process when decoding GIF images.
Fix rendering of wind in Windy.com.
Fix several crashes and rendering issues.

NOTES FROM 2.18.3

What’s new in the WebKitGTK+ 2.18.3 release?
Improve calculation of font metrics to prevent scrollbars from being shown unnecessarily in some cases.
Fix handling of null capabilities in WebDriver implementation.
Security fixes: CVE-2017-13798, CVE-2017-13788, CVE-2017-13803.

SECURITY STUFF

CVE-2017-13788
Versions affected: WebKitGTK+ before 2.18.3.
Credit to xisigr of Tencent’s Xuanwu Lab (tencent.com).
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
CVE-2017-13798
Versions affected: WebKitGTK+ before 2.18.3.
Credit to Ivan Fratric of Google Project Zero.
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
CVE-2017-13803
Versions affected: WebKitGTK+ before 2.18.3.
Credit to chenqin (陈钦) of Ant-financial Light-Year Security.
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.

comment:3 by Douglas R. Reno, 6 years ago

Resolution: fixed
Status: assignedclosed

Fixed at r19475

Last edited 6 years ago by Douglas R. Reno (previous) (diff)
Note: See TracTickets for help on using tickets.