USN-3743-1: WebKitGTK+ vulnerabilities
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-3743-1?
The severity of USN-3743-1 is high.
How can a remote attacker exploit the vulnerabilities in USN-3743-1?
A remote attacker can exploit the vulnerabilities in USN-3743-1 by tricking a user into viewing a malicious website, which can lead to various web browser security issues including cross-site scripting attacks and denial of service.
Which software versions are affected by USN-3743-1?
The software versions affected by USN-3743-1 are libjavascriptcoregtk-4.0-18 (version 2.20.5-0ubuntu0.18.04.1) and libwebkit2gtk-4.0-37 (version 2.20.5-0ubuntu0.18.04.1) on Ubuntu 18.04, as well as libjavascriptcoregtk-4.0-18 (version 2.20.5-0ubuntu0.16.04.1) and libwebkit2gtk-4.0-37 (version 2.20.5-0ubuntu0.16.04.1) on Ubuntu 16.04.
How do I fix the vulnerabilities in USN-3743-1?
To fix the vulnerabilities in USN-3743-1, you need to update the affected software packages to the specified remedy versions: libjavascriptcoregtk-4.0-18 (version 2.20.5-0ubuntu0.18.04.1) and libwebkit2gtk-4.0-37 (version 2.20.5-0ubuntu0.18.04.1) on Ubuntu 18.04, as well as libjavascriptcoregtk-4.0-18 (version 2.20.5-0ubuntu0.16.04.1) and libwebkit2gtk-4.0-37 (version 2.20.5-0ubuntu0.16.04.1) on Ubuntu 16.04.
Where can I find more information about USN-3743-1?
More information about USN-3743-1 can be found on the Ubuntu Security Notices website: [link 1](https://ubuntu.com/security/CVE-2018-12911), [link 2](https://ubuntu.com/security/CVE-2018-4246), [link 3](https://ubuntu.com/security/CVE-2018-4261).