Re: [webkit-gtk] Fix CVE-2023-32435 for webkitgtk 2.38.6

2023-09-06 Thread 不会弹吉他的KK
On Wed, Sep 6, 2023 at 9:46 PM Michael Catanzaro wrote: > On Wed, Sep 6 2023 at 04:23:17 PM +0800, 不会弹吉他的KK > wrote: > > My question is > > 1. Does webkitgtk 2.38.6 is vulnerable to CVE-2023-32435? > > No clue, sorry. > > > 2. If YES, how to deal the patches with the 2 new files? If just > >

Re: [webkit-gtk] Fix CVE-2023-32435 for webkitgtk 2.38.6

2023-09-06 Thread Michael Catanzaro
On Wed, Sep 6 2023 at 04:23:17 PM +0800, 不会弹吉他的KK wrote: My question is 1. Does webkitgtk 2.38.6 is vulnerable to CVE-2023-32435? No clue, sorry. 2. If YES, how to deal the patches with the 2 new files? If just ignore and only patch file Source/JavaScriptCore/wasm/WasmSectionParser.cpp,

[webkit-gtk] Fix CVE-2023-32435 for webkitgtk 2.38.6

2023-09-06 Thread 不会弹吉他的KK
Hi All, CVE-2023-32435 has been fixed in webkitgtk 2.40.0. According to https://bugs.webkit.org/show_bug.cgi?id=251890, the commit is at https://github.com/WebKit/WebKit/commit/50c7aaec2f53ab3b960f1b299aad5009df6f1967 . It patches 3 files, but 2 of them are created/added in 2.40.0 and do NOT exist