Skip to content

Commit

Permalink
Merge branch 'master' into csaavedra/get-wpe.md
Browse files Browse the repository at this point in the history
  • Loading branch information
bkardell authored Jul 25, 2023
2 parents 36208d2 + a8342d5 commit 8f5851e
Show file tree
Hide file tree
Showing 2 changed files with 61 additions and 0 deletions.
38 changes: 38 additions & 0 deletions _posts/2023-07-21-security-advisory-2023-0006.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
---
layout: post
title: WebKitGTK and WPE WebKit Security Advisory WSA-2023-0006
permalink: /security/WSA-2023-0006.html
tags: WSA
---

* Date Reported: **July 21, 2023**

* Advisory ID: **WSA-2023-0006**

* CVE identifiers: [CVE-2023-37450](#CVE-2023-37450), [CVE-2023-32393](#CVE-2023-32393).


Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

* <a name="CVE-2023-37450" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-37450">CVE-2023-37450</a>
* Versions affected: WebKitGTK and WPE WebKit before 2.40.4.
* Credit to an anonymous researcher.
* Impact: Processing web content may lead to arbitrary code execution.
Apple is aware of a report that this issue may have been actively
exploited. Description: The issue was addressed with improved
checks.

* <a name="CVE-2023-32393" href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32393">CVE-2023-32393</a>
* Versions affected: WebKitGTK and WPE WebKit before 2.40.0.
* Credit to Francisco Alonso (@revskills).
* Impact: Processing web content may lead to arbitrary code execution.
Description: The issue was addressed with improved memory handling.


We recommend updating to the latest stable versions of WebKitGTK and WPE
WebKit. It is the best way to ensure that you are running safe versions
of WebKit. Please check our websites for information about the latest
stable releases.

Further information about WebKitGTK and WPE WebKit security advisories can be found at:
[https://webkitgtk.org/security.html](https://webkitgtk.org/security.html) or [https://wpewebkit.org/security/](https://wpewebkit.org/security/).
23 changes: 23 additions & 0 deletions release/2023-07-21-wpewebkit-2.40.4-released.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
---
layout: post
title: "WPE WebKit 2.40.4 released"
tags: [release, stable]
package: wpewebkit
version: 2.40.4
permalink: /release/wpewebkit-2.40.4.html
---

This is a bug fix release in the stable 2.40 series.

### What's new in WPE WebKit 2.40.4?

- Fix a bug in JavaScript reading variable arguments in a call.

#### Checksums

<pre>
wpewebkit-2.40.4.tar.xz (36.3 MiB)
md5sum: 89a385f776095483f3479075bf5d4705
sha1sum: f0fde6eaa6de8b6a982a013fe3b962c688d7c381
sha256sum: 34d11fe79522081ecc2d623860c22ddd53ca29a0d08b4c0e55efbdc3e6a9435c
</pre>

0 comments on commit 8f5851e

Please sign in to comment.