First published: Thu Jan 11 2018(Updated: )
It was discovered that speculative execution performed by modern CPUs could leak information through a timing side-channel attack, and that this could be exploited in web browser JavaScript engines. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information from other domains, bypassing same-origin restrictions. (CVE-2017-5753, CVE-2017-5715)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.18.5-0ubuntu0.17.10.1 | 2.18.5-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.18.5-0ubuntu0.17.10.1 | 2.18.5-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.18.5-0ubuntu0.17.04.1 | 2.18.5-0ubuntu0.17.04.1 |
=17.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.18.5-0ubuntu0.17.04.1 | 2.18.5-0ubuntu0.17.04.1 |
=17.04 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.18.5-0ubuntu0.16.04.1 | 2.18.5-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.18.5-0ubuntu0.16.04.1 | 2.18.5-0ubuntu0.16.04.1 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for these WebKitGTK+ vulnerabilities is USN-3530-1.
These vulnerabilities could potentially leak information through a timing side-channel attack and be exploited in web browser JavaScript engines.
The affected software versions include libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.17.10.1 for Ubuntu 17.10, libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.17.10.1 for Ubuntu 17.10, libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.17.04.1 for Ubuntu 17.04, libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.17.04.1 for Ubuntu 17.04, libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.16.04.1 for Ubuntu 16.04, and libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.16.04.1 for Ubuntu 16.04.
To fix these vulnerabilities, you should update the affected software packages to libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.17.10.1 for Ubuntu 17.10, libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.17.10.1 for Ubuntu 17.10, libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.17.04.1 for Ubuntu 17.04, libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.17.04.1 for Ubuntu 17.04, libjavascriptcoregtk-4.0-18 version 2.18.5-0ubuntu0.16.04.1 for Ubuntu 16.04, and libwebkit2gtk-4.0-37 version 2.18.5-0ubuntu0.16.04.1 for Ubuntu 16.04.
Yes, you can find more information about these vulnerabilities at the following references: [1](https://ubuntu.com/security/CVE-2017-5715), [2](https://ubuntu.com/security/CVE-2017-5753), and [3](https://ubuntu.com/security/notices/USN-3594-1).