Security Bulletin
This security bulletin contains information about 12 vulnerabilities.
EUVDB-ID: #VU59207
Risk: High
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-0108
CWE-ID:
CWE-358 - Improperly Implemented Security Check for Standard
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect implementation in Navigation in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU73806
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-32885
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in WebKit when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67199
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-32886
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing web content in WebKit. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67198
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-32912
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in WebKit. A remote attacker can create a specially crafted web page, trick the victim into opening it using the affected software, trigger out-of-bounds read and execute arbitrary code on the target system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU75417
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25358
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebCore::RenderLayer::addChild. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU75416
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25360
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebCore::RenderLayer::renderer. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU75415
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25361
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebCore::RenderLayer::setNextSibling. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU75414
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25362
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebCore::RenderLayer::repaintBlockSelectionGaps. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU75413
Risk: High
CVSSv3.1: 7.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-25363
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebCore::RenderLayer::updateDescendantDependentFlags. A remote attacker can trick the victim to visit a specially crafted web page, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
MitigationUpdate the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74085
Risk: Medium
CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-27932
CWE-ID:
CWE-254 - Security Features
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass Same Origin Policy restrictions.
The vulnerability exists due to improper state management. A remote attacker can trick the victim to visit a specially crafted website and bypass Same Origin Policy restrictions.
Update the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74086
Risk: Medium
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-27954
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can track sensitive user information.
Update the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74604
Risk: Critical
CVSSv3.1: 9.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C]
CVE-ID: CVE-2023-28205
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing HTML content in WebKit. A remote attacker can trick the victim to open a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Note, the vulnerability is being actively exploited in the wild.
Update the affected package webkit2gtk3 to the latest version.
Vulnerable software versionsDevelopment Tools Module: 15-SP4
Desktop Applications Module: 15-SP4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise Real Time 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Linux Enterprise Desktop 15: SP4
Basesystem Module: 15-SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
libwebkit2gtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit-debuginfo: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-32bit-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-32bit: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-32bit: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-5_0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-devel: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-5_0: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_1: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0: before 2.38.6-150400.4.39.1
webkit-jsc-5.0-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_0: before 2.38.6-150400.4.39.1
webkit2gtk3-devel: before 2.38.6-150400.4.39.1
webkit2gtk-4_0-injected-bundles: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_1-0-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_0-37-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-devel: before 2.38.6-150400.4.39.1
webkit-jsc-4.1-debuginfo: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-JavaScriptCore-4_0: before 2.38.6-150400.4.39.1
webkit-jsc-4.1: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-5_0-injected-bundles: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2-5_0: before 2.38.6-150400.4.39.1
libwebkit2gtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit-jsc-4: before 2.38.6-150400.4.39.1
webkit-jsc-4-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-debugsource: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles: before 2.38.6-150400.4.39.1
webkit-jsc-5.0: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_1: before 2.38.6-150400.4.39.1
typelib-1_0-WebKit2WebExtension-4_0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18: before 2.38.6-150400.4.39.1
webkit2gtk3-debugsource: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-4_0-18-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk4-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk-4_1-injected-bundles-debuginfo: before 2.38.6-150400.4.39.1
libwebkit2gtk-4_1-0: before 2.38.6-150400.4.39.1
libjavascriptcoregtk-5_0-0-debuginfo: before 2.38.6-150400.4.39.1
webkit2gtk3-soup2-minibrowser-debuginfo: before 2.38.6-150400.4.39.1
WebKit2GTK-4.0-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-4.1-lang: before 2.38.6-150400.4.39.1
WebKit2GTK-5.0-lang: before 2.38.6-150400.4.39.1
External linkshttp://www.suse.com/support/update/announcement/2023/suse-su-20232065-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
Yes. This vulnerability is being exploited in the wild.