First published: Tue Jul 14 2020(Updated: )
A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.28.3-0ubuntu0.20.04.1 | 2.28.3-0ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.28.3-0ubuntu0.20.04.1 | 2.28.3-0ubuntu0.20.04.1 |
=20.04 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.28.3-0ubuntu0.19.10.1 | 2.28.3-0ubuntu0.19.10.1 |
=19.10 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.28.3-0ubuntu0.19.10.1 | 2.28.3-0ubuntu0.19.10.1 |
=19.10 | ||
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.28.3-0ubuntu0.18.04.1 | 2.28.3-0ubuntu0.18.04.1 |
=18.04 | ||
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.28.3-0ubuntu0.18.04.1 | 2.28.3-0ubuntu0.18.04.1 |
=18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is USN-4422-1.
The libjavascriptcoregtk-4.0-18 and libwebkit2gtk-4.0-37 packages on Ubuntu 20.04, 19.10, and 18.04 are affected.
The recommended remedy is to upgrade to version 2.28.3-0ubuntu0.20.04.1 of the affected packages.
Yes, there are known exploits for this vulnerability.
More information about this vulnerability can be found on the Ubuntu security website.