SUSE SLES12 Security Update : webkit2gtk3 (SUSE-SU-2025:1325-1)

medium Nessus Plugin ID 234546

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2025:1325-1 advisory.

- Update to version 2.48.1
- CVE-2024-54551: improper memory handling may lead to a denial-of-service when processing certain web content (bsc#1240962)
- CVE-2025-24208: permissions issue may lead to a cross-site scripting attack when loading a malicious iframe (bsc#1240961)
- CVE-2025-24209: buffer overflow may lead to crash when processing maliciously crafted web content (bsc#1240964)
- CVE-2025-24213: type confusion issue may lead to memory corruption (bsc#1240963)
- CVE-2025-24216: improper memory handling may lead to an unexpected crash when processing certain web content (bsc#1240986)
- CVE-2025-24264: improper memory handling may lead to unexpected crash when processing certain web content (bsc#1240987)
- CVE-2025-30427: use-after-free issue may lead to an unexpected Safari crash when processing maliciously crafted web content (bsc#1240958)
- CVE-2024-44192: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1239863)
- CVE-2024-54467: a malicious website may exfiltrate data cross-origin due to a cookie management issue (bsc#1239864)

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1239863

https://bugzilla.suse.com/1239864

https://bugzilla.suse.com/1240958

https://bugzilla.suse.com/1240961

https://bugzilla.suse.com/1240962

https://bugzilla.suse.com/1240963

https://bugzilla.suse.com/1240964

https://bugzilla.suse.com/1240986

https://bugzilla.suse.com/1240987

https://lists.suse.com/pipermail/sle-updates/2025-April/039031.html

https://www.suse.com/security/cve/CVE-2024-44192

https://www.suse.com/security/cve/CVE-2024-54467

https://www.suse.com/security/cve/CVE-2024-54551

https://www.suse.com/security/cve/CVE-2025-24208

https://www.suse.com/security/cve/CVE-2025-24209

https://www.suse.com/security/cve/CVE-2025-24213

https://www.suse.com/security/cve/CVE-2025-24216

https://www.suse.com/security/cve/CVE-2025-24264

https://www.suse.com/security/cve/CVE-2025-30427

Plugin Details

Severity: Medium

ID: 234546

File Name: suse_SU-2025-1325-1.nasl

Version: 1.1

Type: local

Agent: unix

Published: 4/17/2025

Updated: 4/17/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-54467

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:typelib-1_0-webkit2-4_0, p-cpe:/a:novell:suse_linux:libjavascriptcoregtk-4_0-18, p-cpe:/a:novell:suse_linux:libwebkit2gtk3-lang, p-cpe:/a:novell:suse_linux:libwebkit2gtk-4_0-37, p-cpe:/a:novell:suse_linux:webkit2gtk3-devel, p-cpe:/a:novell:suse_linux:typelib-1_0-webkit2webextension-4_0, p-cpe:/a:novell:suse_linux:webkit2gtk-4_0-injected-bundles, p-cpe:/a:novell:suse_linux:typelib-1_0-javascriptcore-4_0

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/16/2025

Vulnerability Publication Date: 1/30/2025

Reference Information

CVE: CVE-2024-44192, CVE-2024-54467, CVE-2024-54551, CVE-2025-24208, CVE-2025-24209, CVE-2025-24213, CVE-2025-24216, CVE-2025-24264, CVE-2025-30427

SuSE: SUSE-SU-2025:1325-1