Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 831761 - <net-libs/webkit-gtk-2.34.4: multiple vulnerabilities
Summary: <net-libs/webkit-gtk-2.34.4: multiple vulnerabilities
Status: RESOLVED DUPLICATE of bug 831739
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.openwall.com/lists/oss-se...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-01-22 00:28 UTC by Michael Orlitzky
Modified: 2022-01-22 00:50 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Orlitzky gentoo-dev 2022-01-22 00:28:54 UTC
Several vulnerabilities were discovered in WebKitGTK and WPE WebKit.

CVE-2021-30934
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Dani Biro.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A buffer overflow issue was
    addressed with improved memory handling.

CVE-2021-30936
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher
    lab.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A use after free issue was
    addressed with improved memory management.

CVE-2021-30951
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Pangu.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A use after free issue was
    addressed with improved memory management.

CVE-2021-30952
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to WeBin.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: An integer overflow was
    addressed with improved input validation.

CVE-2021-30953
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to VRIJ.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: An out-of-bounds read was
    addressed with improved bounds checking.

CVE-2021-30954
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Kunlun Lab.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A type confusion issue was
    addressed with improved memory handling.

CVE-2021-30984
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Kunlun Lab.
    Impact: Processing maliciously crafted web content may lead to
    arbitrary code execution. Description: A race condition was
    addressed with improved state handling.

CVE-2022-XXXXX
    Versions affected: WebKitGTK and WPE WebKit before 2.34.4.
    Credit to Martin Bajanik from fingerprintjs.com.
    Impact: A malicious website may exfiltrate data cross-origin.
    Description: A cross-origin issue existed with the IndexedDB. This
    was addressed with improved checking of security origins. 
    Notes: There is a public PoC demonstrating this issue at
    https://safarileaks.com so this issue may have been actively
    exploited. We still don't know the CVE number that will be assigned
    to this issue. We will update this advisory once we know it.

CVE-2021-45481
    Versions affected: WebKitGTK and WPE WebKit before 2.34.0.
    Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher lab.
    Processing maliciously crafted web content may cause an application
    crash due to an incorrect memory allocation in
    WebCore::ImageBufferCairoImageSurfaceBackend::create

CVE-2021-45482
    Versions affected: WebKitGTK and WPE WebKit before 2.32.4.
    Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher lab.
    Processing maliciously crafted web content may cause a memory
    corruption issue (use-after-free) in WebCore::ContainerNode::firstChild

CVE-2021-45483
    Versions affected: WebKitGTK and WPE WebKit before 2.34.0.
    Credit to Chijin Zhou of ShuiMuYuLin Ltd and Tsinghua wingtecher lab.
    Processing maliciously crafted web content may cause a memory
    corruption issue (heap-use-after-free) in WebCore::Frame::page
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-01-22 00:43:07 UTC
Thanks!

Let's handle this in bug 831739 which has most of the CVEs there already and a patch from leio.

*** This bug has been marked as a duplicate of bug 831739 ***
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-01-22 00:44:15 UTC
actually, I think most of those are fixed in earlier versions, just not the first one. they're just slacking with advisories