From 20a5a476a9c52cbe3c7b0dd70345d1ffd4eb0daf Mon Sep 17 00:00:00 2001 From: Adrian Perez de Castro Date: Wed, 25 Sep 2024 23:17:37 +0300 Subject: [PATCH] Remove CVEs for unsupported features in WSA-2024-0005 --- .../2024-09-25-security-advisory-2024-0005.md | 24 +------------------ 1 file changed, 1 insertion(+), 23 deletions(-) diff --git a/security/2024-09-25-security-advisory-2024-0005.md b/security/2024-09-25-security-advisory-2024-0005.md index 03cd557c9..65dcd483c 100644 --- a/security/2024-09-25-security-advisory-2024-0005.md +++ b/security/2024-09-25-security-advisory-2024-0005.md @@ -9,7 +9,7 @@ tags: WSA * Advisory ID: **WSA-2024-0005** -* CVE identifiers: [CVE-2024-23271](#CVE-2024-23271), [CVE-2024-27808](#CVE-2024-27808), [CVE-2024-27820](#CVE-2024-27820), [CVE-2024-27830](#CVE-2024-27830), [CVE-2024-27833](#CVE-2024-27833), [CVE-2024-27838](#CVE-2024-27838), [CVE-2024-27850](#CVE-2024-27850), [CVE-2024-27851](#CVE-2024-27851), [CVE-2024-40857](#CVE-2024-40857), [CVE-2024-40866](#CVE-2024-40866), [CVE-2024-44187](#CVE-2024-44187) +* CVE identifiers: [CVE-2024-23271](#CVE-2024-23271), [CVE-2024-27808](#CVE-2024-27808), [CVE-2024-27820](#CVE-2024-27820), [CVE-2024-27833](#CVE-2024-27833), [CVE-2024-27838](#CVE-2024-27838), [CVE-2024-27851](#CVE-2024-27851), [CVE-2024-40866](#CVE-2024-40866), [CVE-2024-44187](#CVE-2024-44187) Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. @@ -35,13 +35,6 @@ Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. issue was addressed with improved memory handling. * WebKit Bugzilla: 270139 -* CVE-2024-27830 - * Versions affected: WebKitGTK and WPE WebKit before 2.44.3. - * Credit to Joe Rutkowski (@Joe12387) of Crawless and @abrahamjuliot. - * Impact: A maliciously crafted webpage may be able to fingerprint the user. - Description: This issue was addressed through improved state management. - * WebKit Bugzilla: 271159 - * CVE-2024-27833 * Versions affected: WebKitGTK and WPE WebKit before 2.44.2. * Credit to Manfred Paul (@_manfp) working with Trend Micro Zero Day Initiative. @@ -57,14 +50,6 @@ Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. Description: The issue was addressed by adding additional logic. * WebKit Bugzilla: 262337 -* CVE-2024-27850 - * Versions affected: WebKitGTK and WPE WebKit before 2.44.2. - * Credit to an anonymous researcher. - * Impact: A maliciously crafted webpage may be able to fingerprint the user. - Description: This issue was addressed with improvements to the noise injection - algorithm. - * WebKit Bugzilla: 270767 - * CVE-2024-27851 * Versions affected: WebKitGTK and WPE WebKit before 2.44.3. * Credit to Nan Wang (@eternalsakura13) of 360 Vulnerability Research Institute. @@ -72,13 +57,6 @@ Several vulnerabilities were discovered in WebKitGTK and WPE WebKit. execution. Description: The issue was addressed with improved bounds checks. * WebKit Bugzilla: 272106 -* CVE-2024-40857 - * Versions affected: WebKitGTK and WPE WebKit before 2.46.0. - * Credit to Ron Masas. - * Impact: Processing maliciously crafted web content may lead to universal cross site - scripting. Description: This issue was addressed through improved state management. - * WebKit Bugzilla: 268724 - * CVE-2024-40866 * Versions affected: WebKitGTK and WPE WebKit before 2.46.0. * Credit to Hafiizh and YoKo Kho (@yokoacc) of HakTrak.