Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20251204180155.GC2659512@igalia.com>
Date: Thu, 4 Dec 2025 18:01:55 +0200
From: Adrian Perez de Castro <aperez@...lia.com>
To: webkit-gtk@...ts.webkit.org
Cc: webkit-wpe@...ts.webkit.org, security@...kit.org,
 oss-security@...ts.openwall.com
Subject: Re: [webkit-gtk] WebKitGTK and WPE WebKit Security Advisory
 WSA-2025-0009

Hello all,

I have a small amendment to the advisory, please read below.

On Thu, 04 Dec 2025 16:20:45 +0200 Adrian Perez de Castro <aperez@...lia.com> wrote:
> ------------------------------------------------------------------------
> WebKitGTK and WPE WebKit Security Advisory                 WSA-2025-0009
> ------------------------------------------------------------------------
> 
> Date reported           : December 04, 2025
> Advisory ID             : WSA-2025-0009
> WebKitGTK Advisory URL  : https://webkitgtk.org/security/WSA-2025-0009.html
> WPE WebKit Advisory URL : https://wpewebkit.org/security/WSA-2025-0009.html
> CVE identifiers         : CVE-2025-13502, CVE-2025-13947,
>                           CVE-2025-43421, CVE-2025-43458,
>                           CVE-2025-66287.
> 
> Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.
> 
> CVE-2025-13502
>     Versions affected: WebKitGTK and WPE WebKit before 2.50.3.
>     Credit to Stanislav Fort, Aisle Research.
>     Impact: Processing maliciously crafted web content may lead to an
>     unexpected process crash. Description: A buffer overflow was
>     addressed with improved bounds checking.
>     WebKit Bugzilla: 302218

This issue was actually fixed already in version 2.50.2 of both
WPE WebKit and WebKitGTK. The advisories in the respective project's
websites have been updated to reflect this as well.

Cheers,
—Adrián

Download attachment "signature.asc" of type "application/pgp-signature" (196 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.