ID

VAR-202210-1530


CVE

CVE-2022-42824


TITLE

Apple macOS Big Sur and macOS Monterey Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202210-1674

DESCRIPTION

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information. Both Apple macOS Big Sur and Apple macOS Monterey are products of Apple Inc. in the United States. Apple macOS Big Sur is the 17th major release of Apple's operating system macOS for the MAC. Apple macOS Monterey is the 18th major release of macOS, the desktop operating system for the Macintosh. Apple macOS Big Sur and macOS Monterey have security flaws. Safari 16.1 may be obtained from the Mac App Store. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5273-1 security@debian.org https://www.debian.org/security/ Alberto Garcia November 08, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : webkit2gtk CVE ID : CVE-2022-42799 CVE-2022-42823 CVE-2022-42824 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42799 Jihwan Kim and Dohyun Lee discovered that visiting a malicious website may lead to user interface spoofing. For the stable distribution (bullseye), these problems have been fixed in version 2.38.2-1~deb11u1. We recommend that you upgrade your webkit2gtk packages. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2022-10-24-5 watchOS 9.1 watchOS 9.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/HT213491. AppleMobileFileIntegrity Available for: Apple Watch Series 4 and later Impact: An app may be able to modify protected parts of the file system Description: This issue was addressed by removing additional entitlements. CVE-2022-42825: Mickey Jin (@patch1t) AVEVideoEncoder Available for: Apple Watch Series 4 and later Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved bounds checks. CVE-2022-32940: ABC Research s.r.o. CFNetwork Available for: Apple Watch Series 4 and later Impact: Processing a maliciously crafted certificate may lead to arbitrary code execution Description: A certificate validation issue existed in the handling of WKWebView. CVE-2022-42813: Jonathan Zhang of Open Computing Facility (ocf.berkeley.edu) GPU Drivers Available for: Apple Watch Series 4 and later Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2022-32947: Asahi Lina (@LinaAsahi) Kernel Available for: Apple Watch Series 4 and later Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2022-32924: Ian Beer of Google Project Zero Kernel Available for: Apple Watch Series 4 and later Impact: A remote user may be able to cause kernel code execution Description: An out-of-bounds write issue was addressed with improved bounds checking. CVE-2022-42808: Zweig of Kunlun Lab Sandbox Available for: Apple Watch Series 4 and later Impact: An app may be able to access user-sensitive data Description: An access issue was addressed with additional sandbox restrictions. CVE-2022-42811: Justin Bui (@slyd0g) of Snowflake WebKit Available for: Apple Watch Series 4 and later Impact: Visiting a malicious website may lead to user interface spoofing Description: The issue was addressed with improved UI handling. WebKit Bugzilla: 243693 CVE-2022-42799: Jihwan Kim (@gPayl0ad), Dohyun Lee (@l33d0hyun) WebKit Available for: Apple Watch Series 4 and later Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A type confusion issue was addressed with improved memory handling. WebKit Bugzilla: 245058 CVE-2022-42824: Abdulrahman Alqabandi of Microsoft Browser Vulnerability Research, Ryan Shin of IAAI SecLab at Korea University, Dohyun Lee (@l33d0hyun) of DNSLab at Korea University Additional recognition iCloud We would like to acknowledge Tim Michaud (@TimGMichaud) of Moveworks.ai for their assistance. Kernel We would like to acknowledge Peter Nguyen of STAR Labs, Tim Michaud (@TimGMichaud) of Moveworks.ai, Tommy Muir (@Muirey03) for their assistance. WebKit We would like to acknowledge Maddie Stone of Google Project Zero, Narendra Bhati (@imnarendrabhati) of Suma Soft Pvt. Ltd., an anonymous researcher for their assistance. Instructions on how to update your Apple Watch software are available at https://support.apple.com/kb/HT204641 To check the version on your Apple Watch, open the Apple Watch app on your iPhone and select "My Watch > General > About". Alternatively, on your watch, select "My Watch > General > About". All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEBP+4DupqR5Sgt1DB4RjMIDkeNxkFAmNW12IACgkQ4RjMIDke NxmiOw/7BsLUQ4r68XAaamGxUYszLltIfM+9uvHuE6J4/OI+tcAVzHnwZvBYK7AA rT6R8L3wXjIfwvSmWSkkwPVQDaAmyldy/d6ws487f6acXUPIAEfk+jXf7PcfPIaC 6X4bmzjlBXWX7S/UEw7FNSn63oKQJL7bEBgphzZEbCn17gGks6bH5gya0POV9Eol ZaCxoWxOICPjIaOu6hXdh2ehH7P4Nd+U0IKKJ/G/Ig0uV8utqYVrQ/Ant71Rzssd jvgE9wHNnJDExBdmOQUkHA9QqzRizX3NRKTJl7L2DUYNo6mX9F3U06xE5i98wSmu a3aQGKNlQOx8kDlUcngkuggz5JM7ZMxfxJKx/RwZSX2Vj2n6lKrZXxOr99IG+xFu kSKOWPJCe15RBUhJK94WJouSquTzi8dFdrTN69aK3PDWOAmghLP7r945/KHz+FEe vr/CqzzoKMES9GRQAa+kii0AqXbyChU+3QzhxfOM1qsuqgZOGQRenscxKhvKLALS 3/doQB8TmsD9WYZORegqTHpWtes1Aw7R/O6SxOzf1t08wF6JVfRy7wIvMAjirCCW ybI+2YM5I49/r4ubut06a/twGbOd2A6IPrOAObt9eq4x9ZmbMez4S79L4lo9falQ X0Yak1k4beRY5oKTKEpbd4fhSv3Tw1UIsRxOPWRjlcPLxGt6m6U= =PO6h -----END PGP SIGNATURE----- . ========================================================================== Ubuntu Security Notice USN-5730-1 November 17, 2022 webkit2gtk vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in WebKitGTK. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libjavascriptcoregtk-4.0-18 2.38.2-0ubuntu0.22.10.1 libjavascriptcoregtk-4.1-0 2.38.2-0ubuntu0.22.10.1 libjavascriptcoregtk-5.0-0 2.38.2-0ubuntu0.22.10.1 libwebkit2gtk-4.0-37 2.38.2-0ubuntu0.22.10.1 libwebkit2gtk-4.1-0 2.38.2-0ubuntu0.22.10.1 libwebkit2gtk-5.0-0 2.38.2-0ubuntu0.22.10.1 Ubuntu 22.04 LTS: libjavascriptcoregtk-4.0-18 2.38.2-0ubuntu0.22.04.2 libjavascriptcoregtk-4.1-0 2.38.2-0ubuntu0.22.04.2 libwebkit2gtk-4.0-37 2.38.2-0ubuntu0.22.04.2 libwebkit2gtk-4.1-0 2.38.2-0ubuntu0.22.04.2 Ubuntu 20.04 LTS: libjavascriptcoregtk-4.0-18 2.38.2-0ubuntu0.20.04.1 libwebkit2gtk-4.0-37 2.38.2-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK, such as Epiphany, to make all the necessary changes. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: webkit2gtk3 security and bug fix update Advisory ID: RHSA-2023:2834-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2834 Issue date: 2023-05-16 CVE Names: CVE-2022-32886 CVE-2022-32888 CVE-2022-32923 CVE-2022-42799 CVE-2022-42823 CVE-2022-42824 CVE-2022-42826 CVE-2022-42852 CVE-2022-42863 CVE-2022-42867 CVE-2022-46691 CVE-2022-46692 CVE-2022-46698 CVE-2022-46699 CVE-2022-46700 CVE-2023-23517 CVE-2023-23518 CVE-2023-25358 CVE-2023-25360 CVE-2023-25361 CVE-2023-25362 CVE-2023-25363 ==================================================================== 1. Summary: An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: webkit2gtk3-2.38.5-1.el8.src.rpm aarch64: webkit2gtk3-2.38.5-1.el8.aarch64.rpm webkit2gtk3-debuginfo-2.38.5-1.el8.aarch64.rpm webkit2gtk3-debugsource-2.38.5-1.el8.aarch64.rpm webkit2gtk3-devel-2.38.5-1.el8.aarch64.rpm webkit2gtk3-devel-debuginfo-2.38.5-1.el8.aarch64.rpm webkit2gtk3-jsc-2.38.5-1.el8.aarch64.rpm webkit2gtk3-jsc-debuginfo-2.38.5-1.el8.aarch64.rpm webkit2gtk3-jsc-devel-2.38.5-1.el8.aarch64.rpm webkit2gtk3-jsc-devel-debuginfo-2.38.5-1.el8.aarch64.rpm ppc64le: webkit2gtk3-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-debuginfo-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-debugsource-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-devel-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-devel-debuginfo-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-jsc-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-jsc-debuginfo-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-jsc-devel-2.38.5-1.el8.ppc64le.rpm webkit2gtk3-jsc-devel-debuginfo-2.38.5-1.el8.ppc64le.rpm s390x: webkit2gtk3-2.38.5-1.el8.s390x.rpm webkit2gtk3-debuginfo-2.38.5-1.el8.s390x.rpm webkit2gtk3-debugsource-2.38.5-1.el8.s390x.rpm webkit2gtk3-devel-2.38.5-1.el8.s390x.rpm webkit2gtk3-devel-debuginfo-2.38.5-1.el8.s390x.rpm webkit2gtk3-jsc-2.38.5-1.el8.s390x.rpm webkit2gtk3-jsc-debuginfo-2.38.5-1.el8.s390x.rpm webkit2gtk3-jsc-devel-2.38.5-1.el8.s390x.rpm webkit2gtk3-jsc-devel-debuginfo-2.38.5-1.el8.s390x.rpm x86_64: webkit2gtk3-2.38.5-1.el8.i686.rpm webkit2gtk3-2.38.5-1.el8.x86_64.rpm webkit2gtk3-debuginfo-2.38.5-1.el8.i686.rpm webkit2gtk3-debuginfo-2.38.5-1.el8.x86_64.rpm webkit2gtk3-debugsource-2.38.5-1.el8.i686.rpm webkit2gtk3-debugsource-2.38.5-1.el8.x86_64.rpm webkit2gtk3-devel-2.38.5-1.el8.i686.rpm webkit2gtk3-devel-2.38.5-1.el8.x86_64.rpm webkit2gtk3-devel-debuginfo-2.38.5-1.el8.i686.rpm webkit2gtk3-devel-debuginfo-2.38.5-1.el8.x86_64.rpm webkit2gtk3-jsc-2.38.5-1.el8.i686.rpm webkit2gtk3-jsc-2.38.5-1.el8.x86_64.rpm webkit2gtk3-jsc-debuginfo-2.38.5-1.el8.i686.rpm webkit2gtk3-jsc-debuginfo-2.38.5-1.el8.x86_64.rpm webkit2gtk3-jsc-devel-2.38.5-1.el8.i686.rpm webkit2gtk3-jsc-devel-2.38.5-1.el8.x86_64.rpm webkit2gtk3-jsc-devel-debuginfo-2.38.5-1.el8.i686.rpm webkit2gtk3-jsc-devel-debuginfo-2.38.5-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-32886 https://access.redhat.com/security/cve/CVE-2022-32888 https://access.redhat.com/security/cve/CVE-2022-32923 https://access.redhat.com/security/cve/CVE-2022-42799 https://access.redhat.com/security/cve/CVE-2022-42823 https://access.redhat.com/security/cve/CVE-2022-42824 https://access.redhat.com/security/cve/CVE-2022-42826 https://access.redhat.com/security/cve/CVE-2022-42852 https://access.redhat.com/security/cve/CVE-2022-42863 https://access.redhat.com/security/cve/CVE-2022-42867 https://access.redhat.com/security/cve/CVE-2022-46691 https://access.redhat.com/security/cve/CVE-2022-46692 https://access.redhat.com/security/cve/CVE-2022-46698 https://access.redhat.com/security/cve/CVE-2022-46699 https://access.redhat.com/security/cve/CVE-2022-46700 https://access.redhat.com/security/cve/CVE-2023-23517 https://access.redhat.com/security/cve/CVE-2023-23518 https://access.redhat.com/security/cve/CVE-2023-25358 https://access.redhat.com/security/cve/CVE-2023-25360 https://access.redhat.com/security/cve/CVE-2023-25361 https://access.redhat.com/security/cve/CVE-2023-25362 https://access.redhat.com/security/cve/CVE-2023-25363 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202305-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: WebKitGTK+: Multiple Vulnerabilities Date: May 30, 2023 Bugs: #871732, #879571, #888563, #905346, #905349, #905351 ID: 202305-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebkitGTK+, the worst of which could result in arbitrary code execution. Affected packages ================ Package Vulnerable Unaffected ------------------- ------------ ------------ net-libs/webkit-gtk < 2.40.1 >= 2.40.1 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All WebKitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.40.1" References ========= [ 1 ] CVE-2022-32885 https://nvd.nist.gov/vuln/detail/CVE-2022-32885 [ 2 ] CVE-2022-32886 https://nvd.nist.gov/vuln/detail/CVE-2022-32886 [ 3 ] CVE-2022-32888 https://nvd.nist.gov/vuln/detail/CVE-2022-32888 [ 4 ] CVE-2022-32891 https://nvd.nist.gov/vuln/detail/CVE-2022-32891 [ 5 ] CVE-2022-32923 https://nvd.nist.gov/vuln/detail/CVE-2022-32923 [ 6 ] CVE-2022-42799 https://nvd.nist.gov/vuln/detail/CVE-2022-42799 [ 7 ] CVE-2022-42823 https://nvd.nist.gov/vuln/detail/CVE-2022-42823 [ 8 ] CVE-2022-42824 https://nvd.nist.gov/vuln/detail/CVE-2022-42824 [ 9 ] CVE-2022-42826 https://nvd.nist.gov/vuln/detail/CVE-2022-42826 [ 10 ] CVE-2022-42852 https://nvd.nist.gov/vuln/detail/CVE-2022-42852 [ 11 ] CVE-2022-42856 https://nvd.nist.gov/vuln/detail/CVE-2022-42856 [ 12 ] CVE-2022-42863 https://nvd.nist.gov/vuln/detail/CVE-2022-42863 [ 13 ] CVE-2022-42867 https://nvd.nist.gov/vuln/detail/CVE-2022-42867 [ 14 ] CVE-2022-46691 https://nvd.nist.gov/vuln/detail/CVE-2022-46691 [ 15 ] CVE-2022-46692 https://nvd.nist.gov/vuln/detail/CVE-2022-46692 [ 16 ] CVE-2022-46698 https://nvd.nist.gov/vuln/detail/CVE-2022-46698 [ 17 ] CVE-2022-46699 https://nvd.nist.gov/vuln/detail/CVE-2022-46699 [ 18 ] CVE-2022-46700 https://nvd.nist.gov/vuln/detail/CVE-2022-46700 [ 19 ] CVE-2023-23517 https://nvd.nist.gov/vuln/detail/CVE-2023-23517 [ 20 ] CVE-2023-23518 https://nvd.nist.gov/vuln/detail/CVE-2023-23518 [ 21 ] CVE-2023-23529 https://nvd.nist.gov/vuln/detail/CVE-2023-23529 [ 22 ] CVE-2023-25358 https://nvd.nist.gov/vuln/detail/CVE-2023-25358 [ 23 ] CVE-2023-25360 https://nvd.nist.gov/vuln/detail/CVE-2023-25360 [ 24 ] CVE-2023-25361 https://nvd.nist.gov/vuln/detail/CVE-2023-25361 [ 25 ] CVE-2023-25362 https://nvd.nist.gov/vuln/detail/CVE-2023-25362 [ 26 ] CVE-2023-25363 https://nvd.nist.gov/vuln/detail/CVE-2023-25363 [ 27 ] CVE-2023-27932 https://nvd.nist.gov/vuln/detail/CVE-2023-27932 [ 28 ] CVE-2023-27954 https://nvd.nist.gov/vuln/detail/CVE-2023-27954 [ 29 ] CVE-2023-28205 https://nvd.nist.gov/vuln/detail/CVE-2023-28205 [ 30 ] WSA-2022-0009 https://webkitgtk.org/security/WSA-2022-0009.html [ 31 ] WSA-2022-0010 https://webkitgtk.org/security/WSA-2022-0010.html [ 32 ] WSA-2023-0001 https://webkitgtk.org/security/WSA-2023-0001.html [ 33 ] WSA-2023-0002 https://webkitgtk.org/security/WSA-2023-0002.html [ 34 ] WSA-2023-0003 https://webkitgtk.org/security/WSA-2023-0003.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202305-32 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2023 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5

Trust: 1.71

sources: NVD: CVE-2022-42824 // VULHUB: VHN-429655 // PACKETSTORM: 169607 // PACKETSTORM: 169794 // PACKETSTORM: 169556 // PACKETSTORM: 169554 // PACKETSTORM: 169555 // PACKETSTORM: 169932 // PACKETSTORM: 172380 // PACKETSTORM: 172625

AFFECTED PRODUCTS

vendor:applemodel:safariscope:ltversion:16.1

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:11.0

Trust: 1.0

vendor:applemodel:watchosscope:ltversion:9.1

Trust: 1.0

vendor:applemodel:tvosscope:ltversion:16.1

Trust: 1.0

vendor:applemodel:ipadosscope:ltversion:16.0

Trust: 1.0

vendor:applemodel:macosscope:ltversion:13.0

Trust: 1.0

vendor:applemodel:iphone osscope:ltversion:16.1

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:10.0

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:35

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:36

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:37

Trust: 1.0

sources: NVD: CVE-2022-42824

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-42824
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202210-1674
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-42824
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNNVD: CNNVD-202210-1674 // NVD: CVE-2022-42824

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2022-42824

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202210-1674

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202210-1674

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-429655

PATCH

title:Apple macOS Big Sur and macOS Monterey Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=212499

Trust: 0.6

sources: CNNVD: CNNVD-202210-1674

EXTERNAL IDS

db:NVDid:CVE-2022-42824

Trust: 2.5

db:OPENWALLid:OSS-SECURITY/2022/11/04/4

Trust: 1.7

db:PACKETSTORMid:169607

Trust: 0.8

db:PACKETSTORMid:169932

Trust: 0.8

db:PACKETSTORMid:169795

Trust: 0.7

db:CNNVDid:CNNVD-202210-1674

Trust: 0.7

db:AUSCERTid:ESB-2022.6029

Trust: 0.6

db:AUSCERTid:ESB-2022.6248

Trust: 0.6

db:AUSCERTid:ESB-2022.5789

Trust: 0.6

db:AUSCERTid:ESB-2022.6137

Trust: 0.6

db:AUSCERTid:ESB-2022.5305.2

Trust: 0.6

db:PACKETSTORMid:169794

Trust: 0.2

db:PACKETSTORMid:169556

Trust: 0.2

db:PACKETSTORMid:169554

Trust: 0.2

db:PACKETSTORMid:169555

Trust: 0.2

db:PACKETSTORMid:169550

Trust: 0.1

db:VULHUBid:VHN-429655

Trust: 0.1

db:PACKETSTORMid:172380

Trust: 0.1

db:PACKETSTORMid:172625

Trust: 0.1

sources: VULHUB: VHN-429655 // PACKETSTORM: 169607 // PACKETSTORM: 169794 // PACKETSTORM: 169556 // PACKETSTORM: 169554 // PACKETSTORM: 169555 // PACKETSTORM: 169932 // PACKETSTORM: 172380 // PACKETSTORM: 172625 // CNNVD: CNNVD-202210-1674 // NVD: CVE-2022-42824

REFERENCES

url:https://support.apple.com/en-us/ht213495

Trust: 2.3

url:https://www.debian.org/security/2022/dsa-5273

Trust: 1.7

url:https://www.debian.org/security/2022/dsa-5274

Trust: 1.7

url:https://support.apple.com/en-us/ht213488

Trust: 1.7

url:https://support.apple.com/en-us/ht213489

Trust: 1.7

url:https://support.apple.com/en-us/ht213491

Trust: 1.7

url:https://support.apple.com/en-us/ht213492

Trust: 1.7

url:https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2022/11/04/4

Trust: 1.7

url:https://security.gentoo.org/glsa/202305-32

Trust: 1.7

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5lf4lyp725xz7rwopfuv6dgpn4q5duu4/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/aqklegjk3lhakuqolbhnr2di3iugllty/

Trust: 1.0

url:https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/jofkx6buejfecsvfv6p5inqcoyqbb4nz/

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2022-42824

Trust: 0.8

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5lf4lyp725xz7rwopfuv6dgpn4q5duu4/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/aqklegjk3lhakuqolbhnr2di3iugllty/

Trust: 0.7

url:https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/jofkx6buejfecsvfv6p5inqcoyqbb4nz/

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-42799

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2022-42823

Trust: 0.7

url:https://www.auscert.org.au/bulletins/esb-2022.5305.2

Trust: 0.6

url:https://vigilance.fr/vulnerability/webkitgtk-wpe-webkit-five-vulnerabilities-39866

Trust: 0.6

url:https://vigilance.fr/vulnerability/apple-ios-multiple-vulnerabilities-39701

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2022-42824/

Trust: 0.6

url:https://packetstormsecurity.com/files/169932/ubuntu-security-notice-usn-5730-1.html

Trust: 0.6

url:https://packetstormsecurity.com/files/169795/debian-security-advisory-5274-1.html

Trust: 0.6

url:https://packetstormsecurity.com/files/169607/apple-security-advisory-2022-10-27-15.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.6137

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.6248

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.6029

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.5789

Trust: 0.6

url:https://support.apple.com/en-us/ht201222.

Trust: 0.4

url:https://www.apple.com/support/security/pgp/

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2022-32923

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2022-32888

Trust: 0.3

url:https://support.apple.com/ht213495.

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-32922

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42808

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-32924

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42811

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42825

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-32940

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42813

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42863

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42867

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-46699

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-46692

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42826

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-42852

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-46698

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-46691

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2022-32886

Trust: 0.2

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://security-tracker.debian.org/tracker/webkit2gtk

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://support.apple.com/kb/ht204641

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32947

Trust: 0.1

url:https://support.apple.com/ht213491.

Trust: 0.1

url:https://support.apple.com/ht213492.

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/webkit2gtk/2.38.2-0ubuntu0.22.10.1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/webkit2gtk/2.38.2-0ubuntu0.20.04.1

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-5730-1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/webkit2gtk/2.38.2-0ubuntu0.22.04.2

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-25363

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-46698

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-32886

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42826

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-23517

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-46700

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-32888

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-25358

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-23518

Trust: 0.1

url:https://bugzilla.redhat.com/):

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42824

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42823

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2023:2834

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-25362

Trust: 0.1

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-25361

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-32923

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-46692

Trust: 0.1

url:https://access.redhat.com/security/team/contact/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2023-25360

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-46691

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42799

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42863

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42867

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-46699

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-42852

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-25358

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23529

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32891

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2022-0010.html

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2023-0001.html

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2023-0002.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23517

Trust: 0.1

url:https://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2022-0009.html

Trust: 0.1

url:https://webkitgtk.org/security/wsa-2023-0003.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-23518

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-32885

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-25363

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-27932

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-46700

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-27954

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-25361

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-25360

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-42856

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-25362

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2023-28205

Trust: 0.1

sources: VULHUB: VHN-429655 // PACKETSTORM: 169607 // PACKETSTORM: 169794 // PACKETSTORM: 169556 // PACKETSTORM: 169554 // PACKETSTORM: 169555 // PACKETSTORM: 169932 // PACKETSTORM: 172380 // PACKETSTORM: 172625 // CNNVD: CNNVD-202210-1674 // NVD: CVE-2022-42824

CREDITS

Apple

Trust: 0.4

sources: PACKETSTORM: 169607 // PACKETSTORM: 169556 // PACKETSTORM: 169554 // PACKETSTORM: 169555

SOURCES

db:VULHUBid:VHN-429655
db:PACKETSTORMid:169607
db:PACKETSTORMid:169794
db:PACKETSTORMid:169556
db:PACKETSTORMid:169554
db:PACKETSTORMid:169555
db:PACKETSTORMid:169932
db:PACKETSTORMid:172380
db:PACKETSTORMid:172625
db:CNNVDid:CNNVD-202210-1674
db:NVDid:CVE-2022-42824

LAST UPDATE DATE

2025-01-08T21:15:35.165000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-429655date:2022-12-13T00:00:00
db:CNNVDid:CNNVD-202210-1674date:2023-05-31T00:00:00
db:NVDid:CVE-2022-42824date:2023-11-07T03:53:36.900

SOURCES RELEASE DATE

db:VULHUBid:VHN-429655date:2022-11-01T00:00:00
db:PACKETSTORMid:169607date:2022-10-31T15:10:32
db:PACKETSTORMid:169794date:2022-11-09T13:38:05
db:PACKETSTORMid:169556date:2022-10-31T14:20:25
db:PACKETSTORMid:169554date:2022-10-31T14:19:52
db:PACKETSTORMid:169555date:2022-10-31T14:20:08
db:PACKETSTORMid:169932date:2022-11-18T14:26:50
db:PACKETSTORMid:172380date:2023-05-16T17:10:07
db:PACKETSTORMid:172625date:2023-05-30T16:32:33
db:CNNVDid:CNNVD-202210-1674date:2022-10-24T00:00:00
db:NVDid:CVE-2022-42824date:2022-11-01T20:15:24.167