Opened 20 months ago
Closed 20 months ago
#20728 closed enhancement (fixed)
webkitgtk-2.46.4
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 12.3 |
| Component: | BOOK | Version: | git |
| Severity: | normal | Keywords: | |
| Cc: |
Description
New point version.
Change History (4)
comment:1 by , 20 months ago
comment:2 by , 20 months ago
| Priority: | normal → high |
|---|
Security fixes:
CVE-2024-44308
Versions affected: WebKitGTK and WPE WebKit before 2.46.4.
Credit to Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group.
Impact: Processing maliciously crafted web content may lead to arbitrary code
execution. Apple is aware of a report that this issue may have been actively exploited
on Intel-based Mac systems. Description: The issue was addressed with improved checks.
WebKit Bugzilla: 283063
CVE-2024-44309
Versions affected: WebKitGTK and WPE WebKit before 2.46.4.
Credit to Clément Lecigne and Benoît Sevens of Google’s Threat Analysis Group.
Impact: Processing maliciously crafted web content may lead to a cross site
scripting attack. Apple is aware of a report that this issue may have been actively
exploited on Intel-based Mac systems. Description: A cookie management issue was
addressed with improved state management.
WebKit Bugzilla: 283095
Both of these vulnerabilities are known to be exploited in the wild for both remote code execution and cross site scripting. The rating for CVE-2024-44308 is 8.8 high and there are still more reports of exploitation.
comment:3 by , 20 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 20 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 017ff9a4165414dbd0f04064acd69b9f2d0c02c1
SA-12.2-051 issued
Note:
See TracTickets
for help on using tickets.

Changes: