CentOS 8 : GNOME (CESA-2020:4451)

critical Nessus Plugin ID 145826

Synopsis

The remote CentOS host is missing one or more security updates.

Description

The remote CentOS Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CESA-2020:4451 advisory.

- webkitgtk: Incorrect state management leading to universal cross-site scripting (CVE-2019-8625, CVE-2019-8813, CVE-2020-3867)

- webkitgtk: Multiple memory corruption issues leading to arbitrary code execution (CVE-2019-8710, CVE-2019-8720, CVE-2019-8766, CVE-2019-8782, CVE-2019-8783, CVE-2019-8808, CVE-2019-8811, CVE-2019-8812, CVE-2019-8814, CVE-2019-8815, CVE-2019-8816, CVE-2019-8819, CVE-2019-8820, CVE-2019-8823, CVE-2020-3868)

- webkitgtk: Multiple memory corruption issues leading to arbitrary code execution (CVE-2019-8743)

- webkitgtk: Incorrect state management leading to universal cross-site scripting (CVE-2019-8764)

- webkitgtk: Websites could reveal browsing history (CVE-2019-8769)

- webkitgtk: Violation of iframe sandboxing policy (CVE-2019-8771)

- webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution (CVE-2019-8835, CVE-2019-8844)

- webkitgtk: Use after free issue may lead to remote code execution (CVE-2019-8846)

- webkitgtk: Use-after-free issue in accessibility/AXObjectCache.cpp (CVE-2020-10018)

- webkitgtk: use-after-free via crafted web content (CVE-2020-11793)

- gnome-settings-daemon: Red Hat Customer Portal password logged and passed as command line argument when user registers through GNOME control center (CVE-2020-14391)

- LibRaw: lack of thumbnail size range check can lead to buffer overflow (CVE-2020-15503)

- webkitgtk: Denial of service via incorrect memory handling (CVE-2020-3862)

- webkitgtk: Non-unique security origin for DOM object contexts (CVE-2020-3864)

- webkitgtk: Incorrect security check for a top-level DOM object context (CVE-2020-3865)

- webkitgtk: Incorrect processing of file URLs (CVE-2020-3885)

- webkitgtk: Race condition allows reading of restricted memory (CVE-2020-3894)

- webkitgtk: Memory corruption triggered by a malicious web content (CVE-2020-3895)

- webkitgtk: Type confusion leading to arbitrary code execution (CVE-2020-3897, CVE-2020-3901)

- webkitgtk: Memory consumption issue leading to arbitrary code execution (CVE-2020-3899)

- webkitgtk: Memory corruption triggered by a malicious web content (CVE-2020-3900)

- webkitgtk: Input validation issue leading to cross-site script attack (CVE-2020-3902)

- webkitgtk: Logic issue may lead to arbitrary code execution (CVE-2020-9802, CVE-2020-9850)

- webkitgtk: Memory corruption may lead to arbitrary code execution (CVE-2020-9803, CVE-2020-9806, CVE-2020-9807)

- webkitgtk: Logic issue may lead to cross site scripting (CVE-2020-9805)

- webkitgtk: Input validation issue may lead to cross site scripting (CVE-2020-9843)

- webkitgtk: Command injection in web inspector (CVE-2020-9862)

- webkitgtk: Use-after-free may lead to application termination or arbitrary code execution (CVE-2020-9893, CVE-2020-9895)

- webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution (CVE-2020-9894)

- webkitgtk: Access issue in content security policy (CVE-2020-9915)

- webkitgtk: A logic issue may lead to cross site scripting (CVE-2020-9925)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://access.redhat.com/errata/RHSA-2020:4451

Plugin Details

Severity: Critical

ID: 145826

File Name: centos8_RHSA-2020-4451.nasl

Version: 1.7

Type: local

Agent: unix

Published: 2/1/2021

Updated: 5/25/2022

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2020-3899

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2020-9895

Vulnerability Information

CPE: p-cpe:/a:centos:centos:libraw, p-cpe:/a:centos:centos:gnome-settings-daemon, p-cpe:/a:centos:centos:webkit2gtk3, cpe:/o:centos:centos:8, p-cpe:/a:centos:centos:webkit2gtk3-jsc-devel, p-cpe:/a:centos:centos:libraw-devel, p-cpe:/a:centos:centos:webkit2gtk3-devel, p-cpe:/a:centos:centos:webkit2gtk3-jsc

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/4/2020

Vulnerability Publication Date: 9/23/2019

CISA Known Exploited Vulnerability Due Dates: 6/13/2022

Exploitable With

Metasploit (Safari in Operator Side Effect Exploit)

Reference Information

CVE: CVE-2019-8625, CVE-2019-8710, CVE-2019-8720, CVE-2019-8743, CVE-2019-8764, CVE-2019-8766, CVE-2019-8769, CVE-2019-8771, CVE-2019-8782, CVE-2019-8783, CVE-2019-8808, CVE-2019-8811, CVE-2019-8812, CVE-2019-8813, CVE-2019-8814, CVE-2019-8815, CVE-2019-8816, CVE-2019-8819, CVE-2019-8820, CVE-2019-8823, CVE-2019-8835, CVE-2019-8844, CVE-2019-8846, CVE-2020-10018, CVE-2020-11793, CVE-2020-14391, CVE-2020-15503, CVE-2020-3862, CVE-2020-3864, CVE-2020-3865, CVE-2020-3867, CVE-2020-3868, CVE-2020-3885, CVE-2020-3894, CVE-2020-3895, CVE-2020-3897, CVE-2020-3899, CVE-2020-3900, CVE-2020-3901, CVE-2020-3902, CVE-2020-9802, CVE-2020-9803, CVE-2020-9805, CVE-2020-9806, CVE-2020-9807, CVE-2020-9843, CVE-2020-9850, CVE-2020-9862, CVE-2020-9893, CVE-2020-9894, CVE-2020-9895, CVE-2020-9915, CVE-2020-9925

RHSA: 2020:4451