WebkitGTK+: Multiple vulnerabilities Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may lead to arbitrary code execution. WebkitGTK+ 2018-01-07 2018-01-07 641752 remote 2.18.4 2.18.4

WebKitGTK+ is a full-featured port of the WebKit rendering engine.

Multiple vulnerabilities have been discovered in WebkitGTK+. Please review the referenced CVE Identifiers for details.

An attacker, by enticing a user to visit maliciously crafted web content, may be able to execute arbitrary code or cause memory corruption.

There are no known workarounds at this time.

All WebkitGTK+ users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-libs/webkit-gtk-2.18.4:4"
CVE-2017-13856 CVE-2017-13866 CVE-2017-13870 CVE-2017-7156 CVE-2017-7157 jmbailey jmbailey