-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5835-1 security@debian.org https://www.debian.org/security/ Alberto Garcia December 25, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2024-54479 CVE-2024-54502 CVE-2024-54505 CVE-2024-54508 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2024-54479 Seunghyun Lee discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2024-54502 Brendon Tiszka discovered that processing maliciously crafted web content may lead to an unexpected process crash. CVE-2024-54505 Gary Kwong discovered that processing maliciously crafted web content may lead to memory corruption. CVE-2024-54508 linjy, chluo and Xiangwei Zhang discovered that processing maliciously crafted web content may lead to an unexpected process crash. For the stable distribution (bookworm), these problems have been fixed in version 2.46.5-1~deb12u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/webkit2gtk Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmdsg68ACgkQAAyEYu0C 2AJVsw/7BxIXtWkvXQ5ZHrLQnPn46I8hopBsSnrlIXqo+TXISDAt+jdjlrTS9gEu CJHlEpS2YNWKu6NqyjWLfG7j3J7brFrvphadxKyIhgvrQQlGZeZXC6I9YYz4MT3Q 0S9c7mPjAsG26ucTDNs9Zkfr1VWj9jkEa8EPqrIIdsynKatWEQzPWxjQ4tH8bi5I 6clSZHFI95lHck83en4ZVW0TedfsZcXdLm/ku2OpBXK4ay20rd9riunyncBBt4at GPDkWw/QfBb6ym8ZNw1MNd4Bu0ZsiX5r8/4InSikBfhmhfN41rSe88X/DRQuatC4 V0GKU32K3Ib3hcq6QKliBn0nYqNs8hY490tOfQv8xLcLoP3Ab1kZQGcxHiEvIo6n eXUxQU8ATGQ0vVrsR/z1B3HHofFf3PFWFnL+GzH/IuDGfR7fpLqbsIJ4av+D34EX 1lnM6bTlBThhqhm1V+zmsQv9umC6anKmAX9UpNO1tpFLHcvZBjI+SB8M9Ssx5KF+ U50eZT28QjTbT5k3RryE808DlGBnDA6xCU6fJXQS/EYuch9DGs3cCw8N7B4+Sc5q FYlNwwe2E4t9ZKUYRjpc5zQSKZCiPsDQeJjVC+P0gRhGCByZfrmXnJWxlkEl8xdj RpibRaSM3nakbIanVLzebDlBEHzg5jFtJPKafoJifFQElNQ/0HQ= =cTg6 -----END PGP SIGNATURE-----