跳转到帖子

SUSE: CVE-2023-25363: SUSE Linux Security Advisory

recommended_posts

发布于
  • Members

SUSE: CVE-2023-25363: SUSE Linux Security Advisory

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
03/02/2023
Created
05/05/2023
Added
04/28/2023
Modified
01/28/2025

Description

A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.

Solution(s)

  • suse-upgrade-libjavascriptcoregtk-4_0-18
  • suse-upgrade-libjavascriptcoregtk-4_0-18-32bit
  • suse-upgrade-libjavascriptcoregtk-4_1-0
  • suse-upgrade-libjavascriptcoregtk-4_1-0-32bit
  • suse-upgrade-libjavascriptcoregtk-5_0-0
  • suse-upgrade-libwebkit2gtk-4_0-37
  • suse-upgrade-libwebkit2gtk-4_0-37-32bit
  • suse-upgrade-libwebkit2gtk-4_1-0
  • suse-upgrade-libwebkit2gtk-4_1-0-32bit
  • suse-upgrade-libwebkit2gtk-5_0-0
  • suse-upgrade-libwebkit2gtk3-lang
  • suse-upgrade-typelib-1_0-javascriptcore-4_0
  • suse-upgrade-typelib-1_0-javascriptcore-4_1
  • suse-upgrade-typelib-1_0-javascriptcore-5_0
  • suse-upgrade-typelib-1_0-webkit2-4_0
  • suse-upgrade-typelib-1_0-webkit2-4_1
  • suse-upgrade-typelib-1_0-webkit2-5_0
  • suse-upgrade-typelib-1_0-webkit2webextension-4_0
  • suse-upgrade-typelib-1_0-webkit2webextension-4_1
  • suse-upgrade-typelib-1_0-webkit2webextension-5_0
  • suse-upgrade-webkit-jsc-4
  • suse-upgrade-webkit-jsc-4-1
  • suse-upgrade-webkit-jsc-5-0
  • suse-upgrade-webkit2gtk-4-0-lang
  • suse-upgrade-webkit2gtk-4-1-lang
  • suse-upgrade-webkit2gtk-4_0-injected-bundles
  • suse-upgrade-webkit2gtk-4_1-injected-bundles
  • suse-upgrade-webkit2gtk-5-0-lang
  • suse-upgrade-webkit2gtk-5_0-injected-bundles
  • suse-upgrade-webkit2gtk3-devel
  • suse-upgrade-webkit2gtk3-minibrowser
  • suse-upgrade-webkit2gtk3-soup2-devel
  • suse-upgrade-webkit2gtk3-soup2-minibrowser
  • suse-upgrade-webkit2gtk4-devel
  • suse-upgrade-webkit2gtk4-minibrowser

References

  • https://attackerkb.com/topics/cve-2023-25363
  • CVE - 2023-25363
  • 查看数 718
  • 已创建
  • 最后回复