[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4995-1 webkit2gtk -- webkit2gtk

ID: oval:org.secpod.oval:def:605665Date: (C)2021-11-02   (M)2023-12-26
Class: PATCHFamily: unix




The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-30846 Sergei Glazunov discovered that processing maliciously crafted web content may lead to arbitrary code execution CVE-2021-30851 Samuel Gross discovered that processing maliciously crafted web content may lead to code execution CVE-2021-42762 An anonymous reporter discovered a limited Bubblewrap sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined.

Platform:
Debian 10.x
Debian 11.x
Product:
webkit2gtk-driver
gir1.2-javascriptcoregtk-4.0
gir1.2-webkit2-4.0
libjavascriptcoregtk-4.0-18
libjavascriptcoregtk-4.0-bin
libjavascriptcoregtk-4.0-dev
libwebkit2gtk-4.0-37
libwebkit2gtk-4.0-dev
libwebkit2gtk-4.0-doc
Reference:
DSA-4995-1
CVE-2021-30846
CVE-2021-30851
CVE-2021-42762
CVE    3
CVE-2021-30846
CVE-2021-42762
CVE-2021-30851
CPE    3
cpe:/o:debian:debian_linux:10.x
cpe:/a:webkitgtk:libwebkit2gtk-4.0-dev
cpe:/o:debian:debian_linux:11.x

© SecPod Technologies