ArchLinux: 202107-68: wpewebkit: multiple issues
Summary
- CVE-2021-21775 (information disclosure)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. A use-after-free vulnerability exists in the way certain events
are processed for ImageLoader objects of WebKit. A specially crafted
web page can lead to a potential information leak and further memory
corruption. In order to trigger the vulnerability, a victim must be
tricked into visiting a malicious webpage.
- CVE-2021-21779 (information disclosure)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. A use-after-free vulnerability exists in the way that WebKit
GraphicsContext handles certain events. A specially crafted web page
can lead to a potential information leak and further memory corruption.
A victim must be tricked into visiting a malicious web page to trigger
this vulnerability.
- CVE-2021-30663 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution.
- CVE-2021-30665 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution. Apple is aware of a report that this issue
may have been actively exploited.
- CVE-2021-30689 (cross-site scripting)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
universal cross site scripting.
- CVE-2021-30720 (access restriction bypass)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. A malicious website may be able to access restricted ports on
arbitrary servers.
- CVE-2021-30734 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution.
- CVE-2021-30744 (cross-site scripting)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
universal cross site scripting.
- CVE-2021-30749 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution.
- CVE-2021-30795 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution.
- CVE-2021-30797 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to code
execution.
- CVE-2021-30799 (arbitrary code execution)
A security issue has been found in WebKitGTK and WPE WebKit before
2.32.3. Processing maliciously crafted web content may lead to
arbitrary code execution.
Resolution
Upgrade to 2.32.3-1.
# pacman -Syu "wpewebkit>=2.32.3-1"
The problems have been fixed upstream in version 2.32.3.
References
https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-21775 https://talosintelligence.com/vulnerability_reports/TALOS-2021-1229 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-21779 https://talosintelligence.com/vulnerability_reports/TALOS-2021-1238 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30663 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30665 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30689 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30720 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30734 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30744 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30749 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30795 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30797 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30799 https://security.archlinux.org/CVE-2021-21775 https://security.archlinux.org/CVE-2021-21779 https://security.archlinux.org/CVE-2021-30663 https://security.archlinux.org/CVE-2021-30665 https://security.archlinux.org/CVE-2021-30689 https://security.archlinux.org/CVE-2021-30720 https://security.archlinux.org/CVE-2021-30734 https://security.archlinux.org/CVE-2021-30744 https://security.archlinux.org/CVE-2021-30749 https://security.archlinux.org/CVE-2021-30795 https://security.archlinux.org/CVE-2021-30797 https://security.archlinux.org/CVE-2021-30799
![Dist Arch](/images/distros/dist-arch.png)
Workaround
None.