Opened 5 years ago

Closed 5 years ago

Last modified 4 years ago

#16304 closed enhancement (fixed)

webkitgtk-2.36.0

Reported by: Douglas R. Reno Owned by: Bruce Dubbs
Priority: elevated Milestone: 11.2
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by Bruce Dubbs)

New minor version

Change History (4)

comment:1 by Xi Ruoyao, 5 years ago

Highlights of the WebKitGTK 2.36.0 release

  • Add new accessibility implementation using ATSPI DBus interfaces instead of ATK.
  • Add support for requestVideoFrameCallback.
  • Change hardware-acceleration-policy setting default value to always.
  • Add support for media session.
  • Add new API to set HTTP response information to custom uri schemes.
  • Make user interactive threads (event handler, scrolling, …) real time in linux.

comment:2 by Bruce Dubbs, 5 years ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:3 by Bruce Dubbs, 5 years ago

Description: modified (diff)
Resolution: → fixed
Status: assigned → closed

comment:4 by Douglas R. Reno, 4 years ago

Priority: normal → elevated

It looks like this version contained three security fixes. I will file a security advisory shortly

CVE-2022-22624
    Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before 2.34.7
    Credit to Kirin (@Pwnrin) of Tencent Security Xuanwu Lab.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A use after free issue was
    addressed with improved memory management.

CVE-2022-22628
    Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before 2.34.7
    Credit to Kirin (@Pwnrin) of Tencent Security Xuanwu Lab.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A use after free issue was
    addressed with improved memory management.

CVE-2022-22629
    Versions affected: WebKitGTK before 2.36.0 and WPE WebKit before 2.34.7
    Credit to Jeonghoon Shin at Theori working with Trend Micro Zero Day
    Initiative.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A buffer overflow issue was
    addressed with improved memory handling.
Note: See TracTickets for help on using tickets.