webkit2gtk3-2.46.5-1.el8_10.ML.1

エラータID: AXSA:2025-9541:02

Release date: 
Thursday, January 16, 2025 - 10:09
Subject: 
webkit2gtk3-2.46.5-1.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* WebKitGTK: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-54479)
* webkit: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-54502)
* webkit: Processing maliciously crafted web content may lead to memory corruption (CVE-2024-54505)
* webkit: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-54508)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-54479
The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2024-54502
The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.
CVE-2024-54505
A type confusion issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.
CVE-2024-54508
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. webkit2gtk3-2.46.5-1.el8_10.ML.1.src.rpm
    MD5: b4898b71c51574cc468a6f2fb582fe5d
    SHA-256: 87b25cbea1f56221f80a8e50501aa1dd8b158f855eb0071893b52907ce47aa75
    Size: 40.96 MB

Asianux Server 8 for x86_64
  1. webkit2gtk3-2.46.5-1.el8_10.ML.1.i686.rpm
    MD5: 560b63994dd0a3cd984fd3a43914b4ae
    SHA-256: 3074139b565596fabba7419bdcce0753046cab979aa83512a7af78aeb0e79805
    Size: 30.75 MB
  2. webkit2gtk3-2.46.5-1.el8_10.ML.1.x86_64.rpm
    MD5: 0e789edc7787a91aaad4ffec02a149ae
    SHA-256: ec922b4759401dc3f978bd95f567cbc74b857eed60b0343f0955381e99f109b6
    Size: 28.02 MB
  3. webkit2gtk3-devel-2.46.5-1.el8_10.ML.1.i686.rpm
    MD5: 8a23e4ea267f5dac1a93802d6f41e43f
    SHA-256: 82bcbbcd54dbffbfa82a4e065c80d2237f89fb2bc1a7a6b9ccefdb8141cf86a5
    Size: 310.09 kB
  4. webkit2gtk3-devel-2.46.5-1.el8_10.ML.1.x86_64.rpm
    MD5: 02c49aa2ad4f46f501bc8a96fee36776
    SHA-256: 52e72fc0d805e29591c470f3dd121b8adf4725d139f977a182e6be39ef8399af
    Size: 305.82 kB
  5. webkit2gtk3-jsc-2.46.5-1.el8_10.ML.1.i686.rpm
    MD5: d705d7d79ae82d6fd4188ebf3df2a96c
    SHA-256: 2762a612831fe5a81e463fb84e13f53fcb4be6598fd91f5ca0c8530d72f60068
    Size: 4.34 MB
  6. webkit2gtk3-jsc-2.46.5-1.el8_10.ML.1.x86_64.rpm
    MD5: c1c46968a4234e8693b15808bcaeda98
    SHA-256: 34d7281937c82fa463bc6f01fdd8f63aa91c653b42899ae19ecb4e0f19a492e7
    Size: 4.53 MB
  7. webkit2gtk3-jsc-devel-2.46.5-1.el8_10.ML.1.i686.rpm
    MD5: 8020adff2bd3b9ee82a732fdd63907e1
    SHA-256: 883355c11001cd8a294709138d6022d4af5a3bc66ffeaf75e942cf8715543985
    Size: 177.99 kB
  8. webkit2gtk3-jsc-devel-2.46.5-1.el8_10.ML.1.x86_64.rpm
    MD5: b611750ee55f2ca90fd1635ebb6060dd
    SHA-256: e87f18a083a27ad5a1447447ce26b575ca0baa20dc33e4f2d8140dba93dd4fb4
    Size: 168.82 kB