Name | CVE-2024-44187 |
Description | A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-5792-1 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
webkit2gtk (PTS) | jessie | 2.6.2+dfsg1-4 | vulnerable |
stretch | 2.18.6-1~deb9u1 | vulnerable | |
buster (security), buster, buster (lts) | 2.38.6-0+deb10u1 | vulnerable | |
bullseye | 2.44.2-1~deb11u1 | vulnerable | |
bullseye (security) | 2.44.3-1~deb11u1 | vulnerable | |
bookworm | 2.44.2-1~deb12u1 | vulnerable | |
bookworm (security) | 2.46.0-2~deb12u1 | fixed | |
trixie | 2.46.2-1 | fixed | |
sid | 2.46.3-1 | fixed | |
wpewebkit (PTS) | bullseye (security), bullseye | 2.38.6-1~deb11u1 | vulnerable |
bookworm | 2.38.6-1 | vulnerable | |
trixie | 2.46.2-1 | fixed | |
sid | 2.46.3-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
webkit2gtk | source | jessie | (unfixed) | end-of-life | ||
webkit2gtk | source | stretch | (unfixed) | end-of-life | ||
webkit2gtk | source | buster | (unfixed) | end-of-life | ||
webkit2gtk | source | bookworm | 2.46.0-2~deb12u1 | DSA-5792-1 | ||
webkit2gtk | source | (unstable) | 2.46.0-1 | |||
wpewebkit | source | (unstable) | 2.46.1-1 |
[buster] - webkit2gtk <end-of-life> (EOL in buster LTS)
[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
https://webkitgtk.org/security/WSA-2024-0005.html