Red Hat Security Advisory: GNOME security, bug fix, and enhancement update
🔗 CVE IDs covered (29)
📋 Description
CVE-2020-13558 — webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution CVE-2020-24870 — LibRaw: Stack buffer overflow in LibRaw::identify_process_dng_fields() in identify.cpp CVE-2020-27918 — webkitgtk: Use-after-free leading to arbitrary code execution CVE-2020-29623 — webkitgtk: User may be unable to fully delete browsing history CVE-2020-36241 — gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory CVE-2021-1765 — webkitgtk: IFrame sandboxing policy violation CVE-2021-1788 — webkitgtk: Use-after-free leading to arbitrary code execution CVE-2021-1789 — webkitgtk: Type confusion issue leading to arbitrary code execution CVE-2021-1799 — webkitgtk: Access to restricted ports on arbitrary servers via port redirection CVE-2021-1801 — webkitgtk: IFrame sandboxing policy violation CVE-2021-1844 — webkitgtk: Memory corruption issue leading to arbitrary code execution CVE-2021-1870 — webkitgtk: Logic issue leading to arbitrary code execution CVE-2021-1871 — webkitgtk: Logic issue leading to arbitrary code execution CVE-2021-21775 — webkitgtk: Use-after-free in ImageLoader dispatchPendingErrorEvent leading to information leak and possibly code execution CVE-2021-21779 — webkitgtk: Use-after-free in WebCore::GraphicsContext leading to information leak and possibly code execution CVE-2021-21806 — webkitgtk: Use-after-free in fireEventListeners leading to arbitrary code execution CVE-2021-28650 — gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix) CVE-2021-30663 — webkitgtk: Integer overflow leading to arbitrary code execution CVE-2021-30665 — webkitgtk: Memory corruption leading to arbitrary code execution CVE-2021-30682 — webkitgtk: Logic issue leading to leak of sensitive user information CVE-2021-30689 — webkitgtk: Logic issue leading to universal cross site scripting attack CVE-2021-30720 — webkitgtk: Logic issue allowing access to restricted ports on arbitrary servers CVE-2021-30734 — webkitgtk: Memory corruptions leading to arbitrary code execution CVE-2021-30744 — webkitgtk: Cross-origin issue with iframe elements leading to universal cross site scripting attack CVE-2021-30749 — webkitgtk: Memory corruptions leading to arbitrary code execution CVE-2021-30758 — webkitgtk: Type confusion leading to arbitrary code execution CVE-2021-30795 — webkitgtk: Use-after-free leading to arbitrary code execution CVE-2021-30797 — webkitgtk: Insufficient checks leading to arbitrary code execution CVE-2021-30799 — webkitgtk: Memory corruptions leading to arbitrary code execution
🔗 References (72)
- selfhttps://access.redhat.com/errata/RHSA-2021:4381
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1651378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1770302
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1791478
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1813727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1854679
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873297
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1873488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1888404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1894613
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1897932
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1904139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1905000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1909300
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1914925
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1924725
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1925640
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1928794
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1928886
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1935261
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937416
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1938937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1940026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944323
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944329
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944333
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944350
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944859
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944867
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1949176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1951086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952136
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1955754
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1957705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1960705
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962049
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971534
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1972545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1978287
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1978505
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1978612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1980661
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1981420
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986863
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986874
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986883
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986886
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986888
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986900
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986902
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1986906
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1987233
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989035
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1998989
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999120
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004170
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_4381.json