REDHAT-BUG-2238973: Input Validation
WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2022-0007.html CVE identifiers : CVE-2022-32792, CVE-2022-32816, CVE-2022-2294.
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
CVE-2022-32792 Versions affected: WebKitGTK and WPE WebKit before 2.36.5. Credit to Manfred Paul (@manfp) working with Trend Micro Zero Day Initiative. Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: An out-of-bounds write issue was addressed with improved input validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2238973?
The severity of REDHAT-BUG-2238973 is classified as high.
How do I fix REDHAT-BUG-2238973?
To fix REDHAT-BUG-2238973, update WPE WebKit or WebKitGTK to version 2.36.5 or later.
What versions of software are affected by REDHAT-BUG-2238973?
WPE WebKit and WebKitGTK versions below 2.36.5 are affected by REDHAT-BUG-2238973.
What are the CVEs associated with REDHAT-BUG-2238973?
The associated CVEs are CVE-2022-32792 and CVE-2022-32816.
Is there a security advisory related to REDHAT-BUG-2238973?
Yes, the security advisory for REDHAT-BUG-2238973 can be found on the WPE WebKit security page.