Описание
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A flaw was found in webkitgtk. This flaw could allow an attacker to use maliciously crafted web content leading to arbitrary code execution.
Отчет
This flaw is rated as having Moderate impact considering the ability of an attacker to perform arbitrary code execution is limited to cases where a web browser is involved. Red Hat expects customers to not feed untrusted input into WebKit.
Меры по смягчению последствий
This flaw can be mitigated by either disabling JavaScript or by disabling IndexedDB
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | webkitgtk | Affected | ||
Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | ||
Red Hat Enterprise Linux 9 | webkit2gtk3 | Not affected | ||
Red Hat Enterprise Linux 7 | webkitgtk4 | Fixed | RHSA-2022:0059 | 11.01.2022 |
Red Hat Enterprise Linux 8 | webkit2gtk3 | Fixed | RHSA-2021:4097 | 02.11.2021 |
Red Hat Enterprise Linux 8.1 Extended Update Support | webkit2gtk3 | Fixed | RHSA-2021:4686 | 16.11.2021 |
Red Hat Enterprise Linux 8.2 Extended Update Support | webkit2gtk3 | Fixed | RHSA-2022:0075 | 11.01.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A use after free issue was addressed with improved memory management. ...
EPSS
8.8 High
CVSS3