*** This bug is a security vulnerability ***

You have been subscribed to a public security bug by Marc Deslauriers 
(mdeslaur):

Software

WebKitGTK 2.x

ThreatCon

5 (1 week)

CVSS Score

8.8

Impact

System access


CVE Numbers

CVE‑2021‑30846
<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcve.mitre.org%2Fcgi-
bin%2Fcvename.cgi%3Fname%3DCVE-2021-30846&data=04%7C01%7Cngm8fe%40bosch.mail.onmicrosoft.com%7Ca1dc1f8ee3d040efa9b108d9992318fb%7C0ae51e1907c84e4bbb6d648ee58410f4%7C0%7C0%7C637709198284521513%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=9ZkhEOqvyc0fIg%2BK9qrheDqg7Wi%2FFlGQkl47zVGmZow%3D&reserved=0>
, CVE‑2021‑30851
<https://eur03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcve.mitre.org%2Fcgi-
bin%2Fcvename.cgi%3Fname%3DCVE-2021-30851&data=04%7C01%7Cngm8fe%40bosch.mail.onmicrosoft.com%7Ca1dc1f8ee3d040efa9b108d9992318fb%7C0ae51e1907c84e4bbb6d648ee58410f4%7C0%7C0%7C637709198284531466%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=nql%2Bz8xccHrT62SvMLs%2Ba%2BlH5eve7zhsvFxtAFc%2BXiE%3D&reserved=0>


Description

Multiple vulnerabilities have been reported in WebKitGTK, which can be
exploited by malicious people to compromise a vulnerable system.

The vulnerabilities are reported in versions prior to 2.34.1 (please see
the vendor's advisory for a list of affected versions per CVE
identifier).

Affected Software

The following software is affected by the described vulnerability.
Please check the vendor links below to see if exactly your version is
affected.

WebKitGTK 2.x
Please note: If the affected software is not installed on your device / client 
/ server or if the software is CI‑managed, no further action is required by you.

Solution

Update to version 2.34.1.

** Affects: webkitgtk (Ubuntu)
     Importance: Undecided
         Status: New

-- 
WebKitGTK Multiple Arbitrary Code Execution Vulnerabilities
https://bugs.launchpad.net/bugs/1948937
You received this bug notification because you are a member of Ubuntu Bugs, 
which is subscribed to the bug report.

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to