CVE-2021-45483: Use After Free
Published Dec 25, 2021
·Updated
In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-30889.
Affected Software
2 affected componentsFixes available
WebKitGTK WebKitGTK<2.32.4
redhat/webkitgtk<2.32.4
2.32.4
Event History
Dec 25, 2021
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
Description
Jan 13, 2022
Data Sourced
via Red Hat·01:45 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45483.
2
What is the severity of CVE-2021-45483?
The severity of CVE-2021-45483 is medium with a score of 6.5.
3
Which software versions are affected by CVE-2021-45483?
Versions up to but excluding 2.32.4 of WebKitGTK are affected by CVE-2021-45483.
4
What is the type of vulnerability represented by CVE-2021-45483?
CVE-2021-45483 is a use-after-free vulnerability in WebCore::Frame::page.
5
Where can I find more information about CVE-2021-45483?
You can find more information about CVE-2021-45483 at the following references: [http://www.openwall.com/lists/oss-security/2022/01/21/2](http://www.openwall.com/lists/oss-security/2022/01/21/2), [https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.32.3](https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.32.3).