Red Hat Security Advisory: GNOME security, bug fix, and enhancement update
🔗 CVE IDs covered (57)
📋 Description
CVE-2019-8625 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8710 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8720 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8743 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8764 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8766 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8769 — webkitgtk: Websites could reveal browsing history CVE-2019-8771 — webkitgtk: Violation of iframe sandboxing policy CVE-2019-8782 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8783 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8808 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8811 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8812 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8813 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2019-8814 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8815 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8816 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8819 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8820 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8823 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2019-8835 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2019-8844 — webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution CVE-2019-8846 — webkitgtk: Use after free issue may lead to remote code execution CVE-2020-3862 — webkitgtk: Denial of service via incorrect memory handling CVE-2020-3864 — webkitgtk: Non-unique security origin for DOM object contexts CVE-2020-3865 — webkitgtk: Incorrect security check for a top-level DOM object context CVE-2020-3867 — webkitgtk: Incorrect state management leading to universal cross-site scripting CVE-2020-3868 — webkitgtk: Multiple memory corruption issues leading to arbitrary code execution CVE-2020-3885 — webkitgtk: Incorrect processing of file URLs CVE-2020-3894 — webkitgtk: Race condition allows reading of restricted memory CVE-2020-3895 — webkitgtk: Memory corruption triggered by a malicious web content CVE-2020-3897 — webkitgtk: Type confusion leading to arbitrary code execution CVE-2020-3899 — webkitgtk: Memory consumption issue leading to arbitrary code execution CVE-2020-3900 — webkitgtk: Memory corruption triggered by a malicious web content CVE-2020-3901 — webkitgtk: Type confusion leading to arbitrary code execution CVE-2020-3902 — webkitgtk: Input validation issue leading to cross-site script attack CVE-2020-9802 — webkitgtk: Logic issue may lead to arbitrary code execution CVE-2020-9803 — webkitgtk: Memory corruption may lead to arbitrary code execution CVE-2020-9805 — webkitgtk: Logic issue may lead to cross site scripting CVE-2020-9806 — webkitgtk: Memory corruption may lead to arbitrary code execution CVE-2020-9807 — webkitgtk: Memory corruption may lead to arbitrary code execution CVE-2020-9843 — webkitgtk: Input validation issue may lead to cross site scripting CVE-2020-9850 — webkitgtk: Logic issue may lead to arbitrary code execution CVE-2020-9862 — webkitgtk: Command injection in web inspector CVE-2020-9893 — webkitgtk: Use-after-free may lead to application termination or arbitrary code execution CVE-2020-9894 — webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution CVE-2020-9895 — webkitgtk: Use-after-free may lead to application termination or arbitrary code execution CVE-2020-9915 — webkitgtk: Access issue in content security policy CVE-2020-9925 — webkitgtk: A logic issue may lead to cross site scripting CVE-2020-9952 — webkitgtk: input validation issue may lead to a cross site scripting CVE-2020-10018 — webkitgtk: Use-after-free issue in accessibility/AXObjectCache.cpp CVE-2020-11793 — webkitgtk: use-after-free via crafted web content CVE-2020-14391 — gnome-settings-daemon: Red Hat Customer Portal password logged and passed as command line argument when user registers through GNOME control center CVE-2020-15503 — LibRaw: lack of thumbnail size range check can lead to buffer overflow CVE-2021-30666 — webkitgtk: Buffer overflow leading to arbitrary code execution CVE-2021-30761 — webkitgtk: Memory corruption leading to arbitrary code execution CVE-2021-30762 — webkitgtk: Use-after-free leading to arbitrary code execution
🔗 References (104)
- selfhttps://access.redhat.com/errata/RHSA-2020:4451
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1207179
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1566027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1569868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1652178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1656262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1668895
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706008
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1706076
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1715845
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1719937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1758891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1775345
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1778579
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1779691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1794045
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1804719
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1805929
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1811721
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1814820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816070
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816678
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816684
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1816686
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1817143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820759
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1820760
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1824362
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1827030
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1829369
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1832347
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1833158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837381
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837413
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1837648
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1840080
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1840788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1843486
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1844578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1846191
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847061
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847062
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1847203
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853477
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854734
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1866332
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1868260
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1872270
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873093
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873963
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876462
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876463
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876465
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876468
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876470
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876472
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876473
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876476
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876516
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876518
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876522
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876537
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876540
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876543
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876548
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876549
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876550
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876552
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876553
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876555
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876556
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876590
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876607
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876611
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1876619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1877853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879535
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879538
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879540
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879559
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879563
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879564
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879566
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1879568
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1880339
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4451.json