CVE-2021-21775
07.07.2021, 22:15
A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.Enginsight
| Vendor | Product | Version |
|---|---|---|
| webkitgtk | webkitgtk | 2.30.4 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkit2gtk |
| ||||||||||||||||
| wpewebkit |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit-opensource-src |
| ||||||||||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||||||||||
| webkit2gtk |
| ||||||||||||||||||||||||
| webkitgtk |
| ||||||||||||||||||||||||
| wpewebkit |
|
Common Weakness Enumeration
References