UbuntuUpdates.org

Package "libjavascriptcoregtk-6.0-1"

Name: libjavascriptcoregtk-6.0-1

Description:

JavaScript engine library from WebKitGTK

Latest version: 2.44.3-0ubuntu0.24.04.1
Release: noble (24.04)
Level: security
Repository: main
Head package: webkit2gtk
Homepage: https://webkitgtk.org/

Links


Download "libjavascriptcoregtk-6.0-1"


Other versions of "libjavascriptcoregtk-6.0-1" in Noble

Repository Area Version
base main 2.44.0-2
updates main 2.44.3-0ubuntu0.24.04.1

Changelog

Version: 2.44.3-0ubuntu0.24.04.1 2024-09-09 14:07:06 UTC

  webkit2gtk (2.44.3-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.44.3 to fix security issues.
    - CVE-2024-40776, CVE-2024-40779, CVE-2024-40780, CVE-2024-40782,
      CVE-2024-40789, CVE-2024-4558

 -- Marc Deslauriers <email address hidden> Thu, 05 Sep 2024 09:55:49 -0400

Source diff to previous version
CVE-2024-40776 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and
CVE-2024-40779 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPa
CVE-2024-40780 An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPa
CVE-2024-40782 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and
CVE-2024-40789 An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6
CVE-2024-4558 Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML

Version: 2.44.2-0ubuntu0.24.04.1 2024-05-28 13:07:19 UTC

  webkit2gtk (2.44.2-0ubuntu0.24.04.1) noble-security; urgency=medium

  * Update to 2.44.2 to fix security issues.
    - debian/patches/fix-ftbfs-i386.patch: removed, no longer needed.
    - CVE-2024-27834

 -- Marc Deslauriers <email address hidden> Tue, 21 May 2024 10:01:46 -0400

CVE-2024-27834 The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.



About   -   Send Feedback to @ubuntu_updates