First published: Mon Mar 30 2020(Updated: )
A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.28.0-0ubuntu0.19.10.2 | 2.28.0-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.28.0-0ubuntu0.19.10.2 | 2.28.0-0ubuntu0.19.10.2 |
Ubuntu Linux | =19.10 | |
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.28.0-0ubuntu0.18.04.3 | 2.28.0-0ubuntu0.18.04.3 |
Ubuntu Linux | =18.04 | |
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.28.0-0ubuntu0.18.04.3 | 2.28.0-0ubuntu0.18.04.3 |
Ubuntu Linux | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-4310-1 is high.
If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks and denial of service attacks.
Versions up to and excluding 2.28.0-0ubuntu0.19.10.2 and 2.28.0-0ubuntu0.18.04.3 are affected.
Versions up to and excluding 2.28.0-0ubuntu0.19.10.2 and 2.28.0-0ubuntu0.18.04.3 are affected.
To fix the vulnerability, update to version 2.28.0-0ubuntu0.19.10.2 for Ubuntu 19.10, or version 2.28.0-0ubuntu0.18.04.3 for Ubuntu 18.04.