First published: Mon Jun 18 2018(Updated: )
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.20.3-0ubuntu0.18.04.1 | 2.20.3-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.20.3-0ubuntu0.18.04.1 | 2.20.3-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.20.3-0ubuntu0.17.10.1 | 2.20.3-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.20.3-0ubuntu0.17.10.1 | 2.20.3-0ubuntu0.17.10.1 |
=17.10 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.20.3-0ubuntu0.16.04.1 | 2.20.3-0ubuntu0.16.04.1 |
=16.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.20.3-0ubuntu0.16.04.1 | 2.20.3-0ubuntu0.16.04.1 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-3687-1 is medium.
If a user were tricked into viewing a malicious website, a remote attacker could exploit various security issues related to web browser security.
Update the affected packages to the latest version available for Ubuntu 18.04, 17.10, or 16.04.
The affected software packages are libjavascriptcoregtk-4.0-18 and libwebkit2gtk-4.0-37.
You can find more information about USN-3687-1 on the Ubuntu security website.