CVE-2021-21107
Published: 08 January 2021
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Priority
CVSS 3 base score: 9.6
Status
Package | Release | Status |
---|---|---|
chromium-browser Launchpad, Ubuntu, Debian |
Upstream |
Released
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(code not present)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(code not present)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Needed
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needed
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Does not exist
|
Notes
Author | Note |
---|---|
amurray | The Debian chromium source package is called chromium-browser in Ubuntu |
mdeslaur | starting with Ubuntu 19.10, the chromium-browser package is just a script that installs the Chromium snap |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21107
- https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.html
- https://crbug.com/1153595
- NVD
- Launchpad
- Debian