Arch Linux 803 Published by

A webkit2gtk security update has been released for Arch Linux to address an arbitrary code execution issue.



Arch Linux Security Advisory ASA-202004-23
==========================================

Severity: Critical
Date : 2020-04-28
CVE-ID : CVE-2020-3899
Package : webkit2gtk
Type : arbitrary code execution
Remote : Yes
Link :   https://security.archlinux.org/AVG-1144

Summary
=======

The package webkit2gtk before version 2.28.2-1 is vulnerable to
arbitrary code execution.

Resolution
==========

Upgrade to 2.28.2-1.

# pacman -Syu "webkit2gtk>=2.28.2-1"

The problem has been fixed upstream in version 2.28.2.

Workaround
==========

None.

Description
===========

A memory handling issue has been found in WebKitGTK before 2.28.2 and
WPE WebKit before 2.28.2.

Impact
======

A remote attacker might be able to execute arbitrary code via crafted
web content.

References
==========

  https://webkitgtk.org/security/WSA-2020-0005.html
  https://webkitgtk.org/security/WSA-2020-0005.html#CVE-2020-3899
  https://security.archlinux.org/CVE-2020-3899