QID 354436
Date Published: 2022-12-21
QID 354436: Amazon Linux Security Advisory for webkit2gtk3 : ALAS2022-2022-015
a use-after-free flaw was found in webkitgtk.
Specially crafted web content could use this flaw to trigger an arbitrary code execution when processed. (
( CVE-2021-30809) a confusion type flaw was found in webkitgtk.
( CVE-2021-30818) a logic issue was found in webkitgtk.
An attacker in a privileged network position could use this flaw to bypass hsts. (
( CVE-2021-30823) an out-of-bounds read flaw was found in webkitgtk.
A specially crafted audio file could use this flaw to trigger a disclosure of memory when processed. (
( CVE-2021-30836) a memory corruption issue was addressed with improved memory handling.
This issue is fixed in ios 14.8 and ipados 14.8, safari 15, tvos 15, ios 15 and ipados 15, watchos 8.
Processing maliciously crafted web content may lead to arbitrary code execution. (
( CVE-2021-30846) a memory corruption issue was addressed with improved memory handling.
This issue is fixed in ios 14.8 and ipados 14.8, safari 15, ios 15 and ipados 15.
Processing maliciously crafted web content may lead to code execution. (
( CVE-2021-30848) multiple memory corruption issues were addressed with improved memory handling.
This issue is fixed in ios 14.8 and ipados 14.8, watchos 8, safari 15, tvos 15, ios 15 and ipados 15, itunes 12.12 for windows.
( CVE-2021-30849) a memory corruption vulnerability was addressed with improved locking.
This issue is fixed in safari 15, tvos 15, watchos 8, ios 15 and ipados 15.
( CVE-2021-30851) a flaw was found in webkitgtk.
This flaw could allow an attacker to use maliciously crafted web content leading to arbitrary code execution. (
( CVE-2021-30858) a flaw was found in the way webkitgtk performed css compositing.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2022-2022-015 -
alas.aws.amazon.com/AL2022/ALAS-2022-015.html
CVEs related to QID 354436
Advisory ID | Software | Component | Link |
---|---|---|---|
ALAS2022-2022-015 | amazon linux 2022 |
![]() |