Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-42762

Опубликовано: 20 окт. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.6
CVSS3: 5.3

Описание

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-apps/noble

ignored

esm-infra-legacy/trusty

DNE

esm-infra/xenial

ignored

focal

ignored

hirsute

ignored

end of life

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/bionic

ignored

esm-apps/xenial

ignored

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

code not enabled
devel

released

2.34.1-1ubuntu1
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

code not enabled
esm-infra/focal

not-affected

2.34.1-0ubuntu0.20.04.1
esm-infra/xenial

ignored

focal

released

2.34.1-0ubuntu0.20.04.1
hirsute

released

2.34.1-0ubuntu0.21.04.1
impish

released

2.34.1-0ubuntu0.21.10.1
jammy

released

2.34.1-1ubuntu1

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/bionic

ignored

esm-apps/xenial

ignored

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

hirsute

DNE

impish

DNE

jammy

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-infra-legacy/trusty

DNE

focal

ignored

hirsute

ignored

end of life
impish

ignored

end of life
jammy

ignored

kinetic

DNE

Показывать по

EPSS

Процентиль: 1%
0.00009
Низкий

4.6 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 3 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
nvd
больше 3 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.

CVSS3: 5.3
debian
больше 3 лет назад

BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allow ...

suse-cvrf
больше 3 лет назад

Security update for webkit2gtk3

suse-cvrf
больше 3 лет назад

Security update for webkit2gtk3

EPSS

Процентиль: 1%
0.00009
Низкий

4.6 Medium

CVSS2

5.3 Medium

CVSS3

Уязвимость CVE-2021-42762