CVE-2021-45481: Medium severity oracle webkitgtk4-jsc vulnerability
Published Dec 25, 2021
·Updated
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.
Affected Software
2 affected componentsFixes available
WebKitGTK WebKitGTK<2.32.4
redhat/webkitgtk<2.32.4
2.32.4
Event History
Dec 25, 2021
CVE Published
via MITRE·12:04 AM
Data Sourced
via MITRE·12:04 AM
Description
Jan 13, 2022
Data Sourced
via Red Hat·01:42 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this WebKitGTK issue?
The vulnerability ID for this issue is CVE-2021-45481.
2
What is the title of the vulnerability?
The title of the vulnerability is 'In WebKitGTK before 2.32.4 there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create'.
3
What is the severity of CVE-2021-45481?
The severity of CVE-2021-45481 is medium with a CVSS score of 6.5.
4
Which software versions are affected by CVE-2021-45481?
Versions up to 2.32.4 of WebKitGTK are affected by CVE-2021-45481.
5
How can I fix the vulnerability in my WebKitGTK installation?
To fix the vulnerability, you should update WebKitGTK to version 2.32.4 or later.