RHSA-2011:0177: Moderate: webkitgtk security update
WebKitGTK+ is the port of the portable web rendering engine WebKit to theGTK+ platform.Multiple memory corruption flaws were found in WebKit. Malicious webcontent could cause an application using WebKitGTK+ to crash or,potentially, execute arbitrary code with the privileges of the user runningthe application. (CVE-2010-1782, CVE-2010-1783, CVE-2010-1784,CVE-2010-1785, CVE-2010-1787, CVE-2010-1788, CVE-2010-1790, CVE-2010-1792,CVE-2010-1807, CVE-2010-1814, CVE-2010-3114, CVE-2010-3116, CVE-2010-3119,CVE-2010-3255, CVE-2010-3812, CVE-2010-4198)Multiple use-after-free flaws were found in WebKit. Malicious web contentcould cause an application using WebKitGTK+ to crash or, potentially,execute arbitrary code with the privileges of the user running theapplication. (CVE-2010-1780, CVE-2010-1786, CVE-2010-1793, CVE-2010-1812,CVE-2010-1815, CVE-2010-3113, CVE-2010-3257, CVE-2010-4197, CVE-2010-4204)Two array index errors, leading to out-of-bounds memory reads, were foundin WebKit. Malicious web content could cause an application usingWebKitGTK+ to crash. (CVE-2010-4206, CVE-2010-4577)A flaw in WebKit could allow malicious web content to trick a user intothinking they are visiting the site reported by the location bar, when thepage is actually content controlled by an attacker. (CVE-2010-3115)It was found that WebKit did not correctly restrict read access to imagescreated from the "canvas" element. Malicious web content could allow aremote attacker to bypass the same-origin policy and potentially accesssensitive image data. (CVE-2010-3259)A flaw was found in the way WebKit handled DNS prefetching. Even when itwas disabled, web content containing certain "link" elements could causeWebKitGTK+ to perform DNS prefetching. (CVE-2010-3813)Users of WebKitGTK+ should upgrade to these updated packages, which containWebKitGTK+ version 1.2.6, and resolve these issues. All runningapplications that use WebKitGTK+ must be restarted for this update to takeeffect.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2011:0177?
The severity of RHSA-2011:0177 is categorized as critical due to potential remote code execution risks.
How do I fix RHSA-2011:0177?
To fix RHSA-2011:0177, update to version 1.2.6-2.el6_0 of the affected packages.
What are the affected packages in RHSA-2011:0177?
The affected packages include webkitgtk, webkitgtk-debuginfo, webkitgtk-devel, and webkitgtk-doc.
Could RHSA-2011:0177 allow an attacker to execute arbitrary code?
Yes, RHSA-2011:0177 contains memory corruption flaws that could allow an attacker to execute arbitrary code.
What platforms are impacted by RHSA-2011:0177?
RHSA-2011:0177 impacts systems running the affected versions of packages on the Red Hat Enterprise Linux 6 platform.