USN-4648-1: WebKitGTK vulnerabilities
A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-4648-1?
The severity of USN-4648-1 is high.
How can a remote attacker exploit the vulnerabilities in USN-4648-1?
A remote attacker can exploit the vulnerabilities in USN-4648-1 by tricking a user into viewing a malicious website, which can lead to cross-site scripting attacks and denial of service attacks.
What is the affected software in USN-4648-1?
The affected software in USN-4648-1 includes libjavascriptcoregtk-4.0-18 and libwebkit2gtk-4.0-37.
What is the recommended remedy for USN-4648-1?
The recommended remedy for USN-4648-1 is to update the libjavascriptcoregtk-4.0-18 and libwebkit2gtk-4.0-37 packages to version 2.30.3-0ubuntu0.20.10.1 (for Ubuntu 20.10), 2.30.3-0ubuntu0.20.04.1 (for Ubuntu 20.04), or 2.30.3-0ubuntu0.18.04.1 (for Ubuntu 18.04).
Where can I find more information about the vulnerabilities in USN-4648-1?
You can find more information about the vulnerabilities in USN-4648-1 on the Ubuntu website: [link1] [link2] [link3].