Bug 14049

Summary: [CVE21] webkitgtk2 v.2.4.11 CVE found
Product: [ROSA-based products] ROSA Fresh Reporter: Vladimir Potapov <v.potapov>
Component: Preinstalled software in the ISOAssignee: ROSA Linux Bugs <bugs>
Status: RESOLVED WONTFIX QA Contact: ROSA Linux Bugs <bugs>
Severity: blocker    
Priority: Highest CC: a.proklov
Version: AllFlags: v.potapov: secteam_verified?
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2019-8375
Whiteboard:
Platform: --- ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Vladimir Potapov 2023-11-28 07:50:36 MSK
CVE-2019-8375
The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products, does not prevent the script dialog size from exceeding the web view size, which allows remote attackers to cause a denial of service (Buffer Overflow) or possibly have unspecified other impact, related to UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, and UIProcess/API/gtk/WebKitWebViewGtk.cpp, as demonstrated by GNOME Web (aka Epiphany).
Comment 1 Vladimir Potapov 2023-11-28 07:54:32 MSK
Base Score: 9.8 CRITICAL
Comment 2 Aleksandr Proklov 2023-11-28 08:08:01 MSK
Нету в нашей версии 2.4.11 этих файлов и кода такого тоже нету.
UIProcess/API/gtk/WebKitScriptDialogGtk.cpp, 
UIProcess/API/gtk/WebKitScriptDialogImpl.cpp, 
and UIProcess/API/gtk/WebKitWebViewGtk.cpp

вот патч видимо https://trac.webkit.org/changeset/241515/webkit
Comment 3 Vladimir Potapov 2023-11-28 14:49:36 MSK
Там еще CVE-2019-8375
И опять критикал и опять с эксплойтом :-(
Comment 4 Vladimir Potapov 2023-11-28 14:51:14 MSK
(In reply to Vladimir Potapov from comment #3)
> Там еще CVE-2019-8375
> И опять критикал и опять с эксплойтом :-(
Стоп, это дубль :-)
Comment 5 Vladimir Potapov 2023-12-01 16:48:29 MSK
Часть зависимостей отвязана, в процессе перевода в contrib
Comment 6 Vladimir Potapov 2023-12-06 10:04:45 MSK
Пакет выброшен из проверяемых, образы от него отвязаны.