Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 10 Buster DSA-4945-1 Critical: Webkit2gtk Memory Flaws

debian
Calendar Grey July 28, 2021
Debian Logo
An exploit in webkit2gtk has been identified, causing risks of data exposure and unauthorized code execution. Immediate upgrade advised.
The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-21775

Summary

The following vulnerabilities have been discovered in the webkit2gtk
web engine:

CVE-2021-21775

Marcin Towalski discovered that a specially crafted web page can
lead to a potential information leak and further memory
corruption. In order to trigger the vulnerability, a victim must
be tricked into visiting a malicious webpage.

CVE-2021-21779

Marcin Towalski discovered that a specially crafted web page can
lead to a potential information leak and further memory
corruption. In order to trigger the vulnerability, a victim must
be tricked into visiting a malicious webpage.

CVE-2021-30663

An anonymous researcher discovered that processing maliciously
crafted web content may lead to arbitrary code execution.

CVE-2021-30665

yangkang discovered that processing maliciously crafted web
content may lead to arbitrary code execution. Apple is aware of a
report that this issue may have been actively exploited.

CVE-2021-30689

An anonymous researcher discovered th...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: webkit2gtk
CVE ID: CVE-2021-21775 CVE-2021-21779 CVE-2021-30663 CVE-2021-30665

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here