Security update for webkit2gtk3

Announcement ID: SUSE-SU-2022:4284-1
Rating: important
References:
Cross-References:
CVSS scores:
  • CVE-2022-32888 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • CVE-2022-32888 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • CVE-2022-32923 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • CVE-2022-32923 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • CVE-2022-42799 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • CVE-2022-42799 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • CVE-2022-42823 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • CVE-2022-42823 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • CVE-2022-42824 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • CVE-2022-42824 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products:
  • SUSE CaaS Platform 4.0
  • SUSE Enterprise Storage 6
  • SUSE Linux Enterprise High Performance Computing 15
  • SUSE Linux Enterprise High Performance Computing 15 LTSS 15
  • SUSE Linux Enterprise High Performance Computing 15 SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 ESPOS 15-SP1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
  • SUSE Linux Enterprise Server 15
  • SUSE Linux Enterprise Server 15 LTSS 15
  • SUSE Linux Enterprise Server 15 SP1
  • SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
  • SUSE Linux Enterprise Server ESPOS 15
  • SUSE Linux Enterprise Server for SAP Applications 15
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1

An update that solves five vulnerabilities can now be installed.

Description:

Security fixes:

  • CVE-2022-32888: Fixed possible arbitrary code execution via maliciously crafted web content (bsc#1205121).
  • CVE-2022-32923: Fixed possible information leak via maliciously crafted web content (bsc#1205122).
  • CVE-2022-42799: Fixed user interface spoofing when visiting a malicious website (bsc#1205123).
  • CVE-2022-42823: Fixed possible arbitrary code execution via maliciously crafted web content (bsc#1205120).
  • CVE-2022-42824: Fixed possible sensitive user information leak via maliciously crafted web content (bsc#1205124).

Update to version 2.38.2:

  • Fix scrolling issues in some sites having fixed background.
  • Fix prolonged buffering during progressive live playback.
  • Fix the build with accessibility disabled.
  • Fix several crashes and rendering issues.

Update to version 2.38.1:

  • Make xdg-dbus-proxy work if host session bus address is an abstract socket.
  • Use a single xdg-dbus-proxy process when sandbox is enabled.
  • Fix high resolution video playback due to unimplemented changeType operation.
  • Ensure GSubprocess uses posix_spawn() again and inherit file descriptors.
  • Fix player stucking in buffering (paused) state for progressive streaming.
  • Do not try to preconnect on link click when link preconnect setting is disabled.
  • Fix close status code returned when the client closes a WebSocket in some cases.
  • Fix media player duration calculation.
  • Fix several crashes and rendering issues.

Update to version 2.38.0:

  • New media controls UI style.
  • Add new API to set WebView's Content-Security-Policy for web extensions support.
  • Make it possible to use the remote inspector from other browsers using WEBKIT_INSPECTOR_HTTP_SERVER env var.
  • MediaSession is enabled by default, allowing remote media control using MPRIS.
  • Add support for PDF documents using PDF.js.

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Server ESPOS 15
    zypper in -t patch SUSE-SLE-Product-HPC-15-2022-4284=1
  • SUSE Linux Enterprise High Performance Computing 15 LTSS 15
    zypper in -t patch SUSE-SLE-Product-HPC-15-2022-4284=1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 ESPOS 15-SP1
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-4284=1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-4284=1
  • SUSE Linux Enterprise Server 15 LTSS 15
    zypper in -t patch SUSE-SLE-Product-SLES-15-2022-4284=1
  • SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-4284=1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-4284=1
  • SUSE Linux Enterprise Server for SAP Applications 15
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-4284=1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-4284=1
  • SUSE Enterprise Storage 6
    zypper in -t patch SUSE-Storage-6-2022-4284=1
  • SUSE CaaS Platform 4.0
    To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way.

Package List:

  • SUSE Linux Enterprise Server ESPOS 15 (aarch64 x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server ESPOS 15 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 LTSS 15 (aarch64 x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 LTSS 15 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 ESPOS 15-SP1 (aarch64 x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 ESPOS 15-SP1 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 LTSS 15 (aarch64 ppc64le s390x x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 LTSS 15 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1 (x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 SP1 Business Critical Linux 15-SP1 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server for SAP Applications 15 (ppc64le x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server for SAP Applications 15 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE Enterprise Storage 6 (aarch64 x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE Enterprise Storage 6 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1
  • SUSE CaaS Platform 4.0 (x86_64)
    • typelib-1_0-WebKit2WebExtension-4_0-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-debuginfo-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-debuginfo-2.38.2-150000.3.122.1
    • typelib-1_0-WebKit2-4_0-2.38.2-150000.3.122.1
    • webkit2gtk-4_0-injected-bundles-2.38.2-150000.3.122.1
    • libwebkit2gtk-4_0-37-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-2.38.2-150000.3.122.1
    • webkit2gtk3-devel-2.38.2-150000.3.122.1
    • typelib-1_0-JavaScriptCore-4_0-2.38.2-150000.3.122.1
    • webkit2gtk3-debugsource-2.38.2-150000.3.122.1
    • libjavascriptcoregtk-4_0-18-debuginfo-2.38.2-150000.3.122.1
  • SUSE CaaS Platform 4.0 (noarch)
    • libwebkit2gtk3-lang-2.38.2-150000.3.122.1

References: