CVE-2023-43010
WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.
Security Fix(es):
- webkit: visiting a malicious website may lead to address bar spoofing (CVE-2023-42843)
- webkit: heap use-after-free may lead to arbitrary code execution (CVE-2023-42950)
- webkit: processing malicious web content may lead to a denial of service (CVE-2023-42956)
- chromium-browser: Use after free in ANGLE (CVE-2024-4558)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2024:9144, https://access.redhat.com/security/cve/CVE-2023-42843, https://access.redhat.com/security/cve/CVE-2023-42950, https://access.redhat.com/security/cve/CVE-2023-42956, https://access.redhat.com/security/cve/CVE-2023-43010, https://access.redhat.com/security/cve/CVE-2024-4558
