Why are there so many "arbitrary code execution" bugs that constantly keep popping up?
https://www.webkitgtk.org/security/WSA-2020-0006.html Are they as bad as the terse CVE descriptions say they are? On Thu, 09 Jul 2020 10:25:11 +0200, Carlos Garcia Campos wrote: > WebKitGTK 2.28.3 is available for download at: > > https://webkitgtk.org/releases/webkitgtk-2.28.3.tar.xz (20.4MB) > md5sum: a03a4dcd2819baca14fdec5af68b4356 > sha1sum: af1d845d373e67fd666105e798a44e2cadaef83c > sha256sum: > f0898ac072c220e13a4aee819408421a6cb56a6eb89170ceafe52468b0903522 > > This is a bug fix release in the stable 2.28 series. > > What's new in the WebKitGTK 2.28.3 release? > =========================================== > > - Enable kinetic scrolling with async scrolling. > - Fix web process hangs on large GitHub pages. > - Bubblewrap sandbox should not attempt to bind empty paths. > - Fix threading issues in the media player. > - Fix several crashes and rendering issues. > > What is WebKitGTK? > ================== > > WebKitGTK is the GNOME platform port of the WebKit rendering engine. > Offering WebKit's full functionality through a set of GObject-based > APIs, it is suitable for projects requiring any kind of web > integration, from hybrid HTML/CSS applications to full-fledged web > browsers. > > More information > ================ > > If you want to know more about the project or get in touch with us > you may: > > - Visit our website at https://www.webkitgtk.org, or the upstream > site at https://www.webkit.org. People interested in contributing > should read: https://www.webkit.org/coding/contributing.html. > > - Browse the bug list at https://bugs.webkit.org, WebKitGTK bugs are > typically prefixed by "[GTK]." A bug report with a minimal, > reproducible test case is often just as valuable as a patch. > > - Join the #webkit and #webkitgtk IRC channels at irc.freenode.net. > > - Subscribe to the WebKitGTK mailing list, > https://lists.webkit.org/mailman/listinfo/webkit-gtk, or the > WebKit development mailing list, > https://lists.webkit.org/mailman/listinfo/webkit-dev > > Thanks > ====== > > Thanks to all the contributors who made possible this release, they > are far too many to list! > > The WebKitGTK team, > July 09, 2020 > -- > Carlos Garcia Campos > http://pgp.rediris.es:11371/pks/lookup?op=get&search=0xF3D322D0EC4582C3 _______________________________________________ webkit-gtk mailing list webkit-gtk@lists.webkit.org https://lists.webkit.org/mailman/listinfo/webkit-gtk