First published: Mon Feb 12 2024(Updated: )
Several security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libjavascriptcoregtk-4.1-0 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libjavascriptcoregtk-6.0-1 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libwebkit2gtk-4.1-0 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libwebkitgtk-6.0-4 | <2.42.5-0ubuntu0.23.10.2 | 2.42.5-0ubuntu0.23.10.2 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libjavascriptcoregtk-4.0-18 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libjavascriptcoregtk-4.1-0 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libjavascriptcoregtk-6.0-1 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libwebkit2gtk-4.0-37 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libwebkit2gtk-4.1-0 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libwebkitgtk-6.0-4 | <2.42.5-0ubuntu0.22.04.2 | 2.42.5-0ubuntu0.22.04.2 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-6631-1 is classified as critical due to potential remote code execution and denial of service vulnerabilities.
To fix USN-6631-1, update the affected packages to version 2.42.5-0ubuntu0.23.10.2 or 2.42.5-0ubuntu0.22.04.2 depending on your Ubuntu version.
USN-6631-1 affects several WebKitGTK packages including libjavascriptcoregtk and libwebkit2gtk on Ubuntu versions 22.04 and 23.10.
USN-6631-1 could be exploited through cross-site scripting attacks and potentially allow attackers to execute scripts in a user's session.
There is no official workaround recommended for USN-6631-1; applying the patch is crucial for security.