Vulnerability Description
In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnerability than CVE-2021-30889.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webkitgtk | Webkitgtk | < 2.32.4 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/01/21/2Mailing ListThird Party Advisory
- https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.32.3ExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/01/21/2Mailing ListThird Party Advisory
- https://github.com/ChijinZ/security_advisories/tree/master/webkitgtk-2.32.3ExploitThird Party Advisory
FAQ
What is CVE-2021-45481?
CVE-2021-45481 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create, leading to a segmentation violation and application crash, a different vulnera...
How severe is CVE-2021-45481?
CVE-2021-45481 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45481?
Check the references section above for vendor advisories and patch information. Affected products include: Webkitgtk Webkitgtk.