Bug 2231015 (CVE-2023-38133)

Summary: CVE-2023-38133 webkitgtk: disclose sensitive information
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: desktop-qa-list, mcatanza, tpopela
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: webkitgtk 2.40.5 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in WebKitGTK, which exists due to excessive data output in WebKit Process Model. This issue occurs when processing malicious web content, which may lead to sensitive information disclosure to unauthorized attackers.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2231024, 2231025, 2231239    
Bug Blocks: 2231004    

Description Patrick Del Bello 2023-08-10 11:33:17 UTC
Processing web content may disclose sensitive information. Description: The issue was addressed with improved checks.
https://webkitgtk.org/security/WSA-2023-0007.html

Comment 2 TEJ RATHI 2023-08-11 05:28:27 UTC
Created webkitgtk tracking bugs for this issue:

Affects: fedora-all [bug 2231239]

Comment 3 errata-xmlrpc 2023-11-07 08:18:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:6535 https://access.redhat.com/errata/RHSA-2023:6535

Comment 4 errata-xmlrpc 2023-11-14 15:19:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2023:7055 https://access.redhat.com/errata/RHSA-2023:7055