Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Popular YouTuber Says Apple Won't Fix His iMac Pro Damaged While Disassembled and more
· GD Update (SSA:2018-108-01) for Slackware
· Wieshark and Opencv Updates for Debian 7 LTS
· 16 Oracle Linux Updates
· WebKitGTK+ 2.21.1 released
· Dell XPS 13 (9370) Review and more
· macOS 10.13.5 beta 2 now available for developers
· Oracle Linux 7 Update 5 released
· GNOME 3.29.1 released
· OpenSSL and Perl Updates for Ubuntu 12.04 ESM

Upcoming News
· Samsung 860 Pro SSD Review @ Vortez
· Raijintek Orcus 240 @ TechPowerUp
· Team Group Cardea Zero 240 GB @ TechPowerUp
· Guru3D Rig of the Month - January 2018
· Cooler Master MK750 Review @ Vortez
· Seagate Skyhawk 10TB SATA III HDD Review
· Vulkan Continues To Show Its Gaming Strength On Low-End Hardware
· Seagate IronWolf ST12000VN0007 12TB Hard Drive Review @ APH Networks
· Sennheiser Game One @ TechPowerUp
· be quiet! Straight Power 11 1000W Power Supply Review

Linux Compatibility
· Brother DCP-L2540DN
· Sound Blaster E5
· WD Elements 500GB external hard drive
· Canon D660U Flatbad scanner
· Umax Astra 4500 USB Scanner
· Logitech QuickCam Pro 4000
· Dell Latitude E6420
· Creative Sound Blaster Z
· Photosmart 5520
· TB-5300 Slimline Design Tablet

New Forum Topics
· Dale
by: Dale Blinco
on: 2018-02-05 00:26
1 replies, 1186 views

· modem driver needed
by: jongiffen777
on: 2017-12-13 11:11
1 replies, 2360 views

· Need a decent browser for XP Pro!
by: percy
on: 2017-12-05 11:02
2 replies, 4244 views

· Comodo Time Machine + Faronics Deep Freeze
by: Jabberwocky
on: 2017-11-15 23:17
1 replies, 2852 views

· Linux compatablity
by: ibme
on: 2017-10-04 18:05
1 replies, 4766 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android
· Oracle Linux
· Arch Linux

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » September 2009 » USN-836-1: WebKit vulnerabilities

USN-836-1: WebKit vulnerabilities

Posted by Bob on: 09/23/2009 02:40 PM [ Print | 0 comment(s) ]

A new WebKit vulnerabilities update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-836-1 September 23, 2009
webkit vulnerabilities
CVE-2009-0945, CVE-2009-1687, CVE-2009-1690, CVE-2009-1698,
CVE-2009-1711, CVE-2009-1712, CVE-2009-1725
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 8.10
Ubuntu 9.04

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 8.10:
libwebkit-1.0-1 1.0.1-2ubuntu0.2
libwebkit-1.0-1-dbg 1.0.1-2ubuntu0.2
libwebkit-dev 1.0.1-2ubuntu0.2

Ubuntu 9.04:
libwebkit-1.0-1 1.0.1-4ubuntu0.1
libwebkit-1.0-1-dbg 1.0.1-4ubuntu0.1
libwebkit-dev 1.0.1-4ubuntu0.1

After a standard system upgrade you need to restart any applications that
use WebKit, such as Epiphany-webkit and Midori, to effect the necessary
changes.

Details follow:

It was discovered that WebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)

Several flaws were discovered in the WebKit browser and JavaScript engines.
If a user were tricked into viewing a malicious website, a remote attacker
could cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-1687, CVE-2009-1690,
CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)

It was discovered that WebKit did not prevent the loading of local Java
applets. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-1712)


Updated packages for Ubuntu 8.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1-2ubun=
tu0.2.diff.gz
Size/MD5: 25401 ca58f621eec09ea60847fb7eeb18ef2a
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1-2ubun=
tu0.2.dsc
Size/MD5: 1538 ebdb32117beca5fff473ca0c1b065b42
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1.orig.=
tar.gz
Size/MD5: 13418752 4de68a5773998bea14e8939aa341c466

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0.=
1-2ubuntu0.2_all.deb
Size/MD5: 34590 acb9cdfb9608c5f4146ea88eef384e75

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-db=
g_1.0.1-2ubuntu0.2_amd64.deb
Size/MD5: 62592212 df3152f6a40e538e3a267908d83783c0
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1.=
0.1-2ubuntu0.2_amd64.deb
Size/MD5: 3501472 e68f67894e53eb2faa48191ea3953732

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-db=
g_1.0.1-2ubuntu0.2_i386.deb
Size/MD5: 62206938 b7d1dde62360865cbc814122b93d4005
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1.=
0.1-2ubuntu0.2_i386.deb
Size/MD5: 3014500 73a5a3e9985f6d165120c5c3cca6d06b

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1-dbg_1.0.1-2u=
buntu0.2_lpia.deb
Size/MD5: 62284322 75ff8aefee1fdea994f660dab5f6554f
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1_1.0.1-2ubunt=
u0.2_lpia.deb
Size/MD5: 2966170 1c52f1920282c659a0a81a3be44dde7f

Updated packages for Ubuntu 9.04:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1-4ubun=
tu0.1.diff.gz
Size/MD5: 30900 0ea9f48f994b9bd759446a939ff5dca3
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1-4ubun=
tu0.1.dsc
Size/MD5: 1538 31502504b765f1161825ccdb82f71788
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/webkit_1.0.1.orig.=
tar.gz
Size/MD5: 13418752 4de68a5773998bea14e8939aa341c466

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-dev_1.0.=
1-4ubuntu0.1_all.deb
Size/MD5: 34678 5042c01c01e9d128a13d1457c56b0cbd

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-db=
g_1.0.1-4ubuntu0.1_amd64.deb
Size/MD5: 62772554 3026ef7b332447cae68ed4f72b35ddb2
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1.=
0.1-4ubuntu0.1_amd64.deb
Size/MD5: 3502830 0fcd75b07524e2d70f8770ccd5bdc0c3

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1-db=
g_1.0.1-4ubuntu0.1_i386.deb
Size/MD5: 62357024 777eb37c5384472cf9b4adac21f0d116
http://security.ubuntu.com/ubuntu/pool/main/w/webkit/libwebkit-1.0-1_1.=
0.1-4ubuntu0.1_i386.deb
Size/MD5: 3014688 100fd9406ea649edd954f4d154ab4d30

lpia architecture (Low Power Intel Architecture):

http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1-dbg_1.0.1-4u=
buntu0.1_lpia.deb
Size/MD5: 62441454 18aa72b5c443a86153906e5ba4a87e55
http://ports.ubuntu.com/pool/main/w/webkit/libwebkit-1.0-1_1.0.1-4ubunt=
u0.1_lpia.deb
Size/MD5: 2968040 9651199f95dfee6252e2aacde99ebbbf




--=-3HF0opzWsiOULiTXaIDM
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEABECAAYFAkq6ItQACgkQLMAs/0C4zNrFQACfaJ0mrT7x4jPXDV0KgdPVL8Ve
6NsAnRYNc86AEFtg9VOLIJHaDinP2mwH
!Sm
-----END PGP SIGNATURE-----


Bookmark and Share

« Sapphire Radeon HD 5870 1GB in CrossFire · Windows Defender Definition Updates 1.65.1049.0 »

Linux Compatible » News » September 2009 » USN-836-1: WebKit vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2018 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition