{"affected":[{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","libwebkit2gtk3-lang":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","libwebkit2gtk3-lang":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"webkit2gtk3-devel":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"webkit2gtk3-devel":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP3","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libjavascriptcoregtk-4_0-18":"2.18.5-2.18.1","libwebkit2gtk-4_0-37":"2.18.5-2.18.1","typelib-1_0-JavaScriptCore-4_0":"2.18.5-2.18.1","typelib-1_0-WebKit2-4_0":"2.18.5-2.18.1","webkit2gtk-4_0-injected-bundles":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libwebkit2gtk3-lang":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP2","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libwebkit2gtk3-lang":"2.18.5-2.18.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP3","name":"webkit2gtk3","purl":"pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.18.5-2.18.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n\nThis update for webkit2gtk3 fixes the following issues:\n\nUpdate to version 2.18.5:\n\n  + Disable SharedArrayBuffers from Web API.\n  + Reduce the precision of 'high' resolution time to 1ms.\n  + bsc#1075419 - Security fixes: includes improvements to mitigate\n    the effects of Spectre and Meltdown (CVE-2017-5753 and CVE-2017-5715).\n\nUpdate to version 2.18.4:\n\n  + Make WebDriver implementation more spec compliant.\n  + Fix a bug when trying to remove cookies before a web process is\n    spawned.\n  + WebKitWebDriver process no longer links to\n    libjavascriptcoregtk.\n  + Fix several memory leaks in GStreamer media backend.\n  + bsc#1073654 - Security fixes: CVE-2017-13866, CVE-2017-13870,\n    CVE-2017-7156, CVE-2017-13856.\n\nUpdate to version 2.18.3:\n\n  + Improve calculation of font metrics to prevent scrollbars from\n    being shown unnecessarily in some cases.\n  + Fix handling of null capabilities in WebDriver implementation.\n  + Security fixes: CVE-2017-13798, CVE-2017-13788, CVE-2017-13803.\n\nUpdate to version 2.18.2:\n\n  + Fix rendering of arabic text.\n  + Fix a crash in the web process when decoding GIF images.\n  + Fix rendering of wind in Windy.com.\n  + Fix several crashes and rendering issues.\n\nUpdate to version 2.18.1:\n\n  + Improve performance of GIF animations.\n  + Fix garbled display in GMail.\n  + Fix rendering of several material design icons when using the\n    web font.\n  + Fix flickering when resizing the window in Wayland.\n  + Prevent default kerberos authentication credentials from being\n    used in ephemeral sessions.\n  + Fix a crash when webkit_web_resource_get_data() is cancelled.\n  + Correctly handle touchmove and touchend events in\n    WebKitWebView.\n  + Fix the build with enchant 2.1.1.\n  + Fix the build in HPPA and Alpha.\n  + Fix several crashes and rendering issues.\n  + Security fixes: CVE-2017-7081, CVE-2017-7087, CVE-2017-7089,\n    CVE-2017-7090, CVE-2017-7091, CVE-2017-7092, CVE-2017-7093,\n    CVE-2017-7094, CVE-2017-7095, CVE-2017-7096, CVE-2017-7098,\n    CVE-2017-7099, CVE-2017-7100, CVE-2017-7102, CVE-2017-7104,\n    CVE-2017-7107, CVE-2017-7109, CVE-2017-7111, CVE-2017-7117,\n    CVE-2017-7120, CVE-2017-7142.\n\n- Enable gold linker on s390/s390x on SLE15/Tumbleweed.\n","id":"SUSE-SU-2018:0219-1","modified":"2018-01-25T16:38:07Z","published":"2018-01-25T16:38:07Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2018/suse-su-20180219-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1020950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1024749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1050469"},{"type":"REPORT","url":"https://bugzilla.suse.com/1066892"},{"type":"REPORT","url":"https://bugzilla.suse.com/1069925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1073654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1075419"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4692"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-4743"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7587"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7589"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7592"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7623"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7635"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7645"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7652"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7654"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-7656"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13788"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13803"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13866"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2350"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2354"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2355"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2363"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2364"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2366"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2371"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2510"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-2539"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5754"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7011"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7012"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7018"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7019"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7064"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7091"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7092"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7096"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7099"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7100"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7102"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7104"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7107"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7109"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7117"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7120"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-7157"}],"related":["CVE-2016-4692","CVE-2016-4743","CVE-2016-7586","CVE-2016-7587","CVE-2016-7589","CVE-2016-7592","CVE-2016-7598","CVE-2016-7599","CVE-2016-7610","CVE-2016-7623","CVE-2016-7632","CVE-2016-7635","CVE-2016-7639","CVE-2016-7641","CVE-2016-7645","CVE-2016-7652","CVE-2016-7654","CVE-2016-7656","CVE-2017-13788","CVE-2017-13798","CVE-2017-13803","CVE-2017-13856","CVE-2017-13866","CVE-2017-13870","CVE-2017-2350","CVE-2017-2354","CVE-2017-2355","CVE-2017-2356","CVE-2017-2362","CVE-2017-2363","CVE-2017-2364","CVE-2017-2365","CVE-2017-2366","CVE-2017-2369","CVE-2017-2371","CVE-2017-2373","CVE-2017-2496","CVE-2017-2510","CVE-2017-2539","CVE-2017-5715","CVE-2017-5753","CVE-2017-5754","CVE-2017-7006","CVE-2017-7011","CVE-2017-7012","CVE-2017-7018","CVE-2017-7019","CVE-2017-7020","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7038","CVE-2017-7039","CVE-2017-7040","CVE-2017-7041","CVE-2017-7042","CVE-2017-7043","CVE-2017-7046","CVE-2017-7048","CVE-2017-7049","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7059","CVE-2017-7061","CVE-2017-7064","CVE-2017-7081","CVE-2017-7087","CVE-2017-7089","CVE-2017-7090","CVE-2017-7091","CVE-2017-7092","CVE-2017-7093","CVE-2017-7094","CVE-2017-7095","CVE-2017-7096","CVE-2017-7098","CVE-2017-7099","CVE-2017-7100","CVE-2017-7102","CVE-2017-7104","CVE-2017-7107","CVE-2017-7109","CVE-2017-7111","CVE-2017-7117","CVE-2017-7120","CVE-2017-7142","CVE-2017-7156","CVE-2017-7157"],"summary":"Security update for webkit2gtk3","upstream":["CVE-2016-4692","CVE-2016-4743","CVE-2016-7586","CVE-2016-7587","CVE-2016-7589","CVE-2016-7592","CVE-2016-7598","CVE-2016-7599","CVE-2016-7610","CVE-2016-7623","CVE-2016-7632","CVE-2016-7635","CVE-2016-7639","CVE-2016-7641","CVE-2016-7645","CVE-2016-7652","CVE-2016-7654","CVE-2016-7656","CVE-2017-13788","CVE-2017-13798","CVE-2017-13803","CVE-2017-13856","CVE-2017-13866","CVE-2017-13870","CVE-2017-2350","CVE-2017-2354","CVE-2017-2355","CVE-2017-2356","CVE-2017-2362","CVE-2017-2363","CVE-2017-2364","CVE-2017-2365","CVE-2017-2366","CVE-2017-2369","CVE-2017-2371","CVE-2017-2373","CVE-2017-2496","CVE-2017-2510","CVE-2017-2539","CVE-2017-5715","CVE-2017-5753","CVE-2017-5754","CVE-2017-7006","CVE-2017-7011","CVE-2017-7012","CVE-2017-7018","CVE-2017-7019","CVE-2017-7020","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7038","CVE-2017-7039","CVE-2017-7040","CVE-2017-7041","CVE-2017-7042","CVE-2017-7043","CVE-2017-7046","CVE-2017-7048","CVE-2017-7049","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7059","CVE-2017-7061","CVE-2017-7064","CVE-2017-7081","CVE-2017-7087","CVE-2017-7089","CVE-2017-7090","CVE-2017-7091","CVE-2017-7092","CVE-2017-7093","CVE-2017-7094","CVE-2017-7095","CVE-2017-7096","CVE-2017-7098","CVE-2017-7099","CVE-2017-7100","CVE-2017-7102","CVE-2017-7104","CVE-2017-7107","CVE-2017-7109","CVE-2017-7111","CVE-2017-7117","CVE-2017-7120","CVE-2017-7142","CVE-2017-7156","CVE-2017-7157"]}