Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2021-42762
Description:BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2021.3768.1   1.3.6.1.4.1.25623.1.1.4.2021.3603.1   1.3.6.1.4.1.25623.1.0.854285   1.3.6.1.4.1.25623.1.0.704996   1.3.6.1.4.1.25623.1.0.819146   1.3.6.1.4.1.25623.1.0.704995   1.3.6.1.4.1.25623.1.0.854277  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2021-42762
Debian Security Information: DSA-4995 (Google Search)
https://www.debian.org/security/2021/dsa-4995
Debian Security Information: DSA-4996 (Google Search)
https://www.debian.org/security/2021/dsa-4996
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ON5SDVVPVPCAGFPW2GHYATZVZYLPW2L4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H6MGXCX7P5AHWOQ6IRT477UKT7IS4DAD/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M5J2LZQTDX53DNSKSGU7TQYCO2HKSTY4/
https://bugs.webkit.org/show_bug.cgi?id=231479
https://github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4q
http://www.openwall.com/lists/oss-security/2021/10/26/9
http://www.openwall.com/lists/oss-security/2021/10/27/1
http://www.openwall.com/lists/oss-security/2021/10/27/2
http://www.openwall.com/lists/oss-security/2021/10/27/4




© 1998-2025 E-Soft Inc. All rights reserved.