Lucene search

K
freebsdFreeBSD0DA4DB89-84BF-11EE-8290-A8A1599412C6
HistoryNov 14, 2023 - 12:00 a.m.

chromium -- multiple security fixes

2023-11-1400:00:00
vuxml.freebsd.org
15
chromium
security fixes
use after free
garbage collection
navigation
cve-2023-5997
cve-2023-6112
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.4%

Chrome Releases reports:

This update includes 4 security fixes:

[1497997] High CVE-2023-5997: Use after free in Garbage Collection. Reported by Anonymous on 2023-10-31
[1499298] High CVE-2023-6112: Use after free in Navigation. Reported by Sergei Glazunov of Google Project Zero on 2023-11-04

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchchromium< 119.0.6045.159UNKNOWN
FreeBSDanynoarchungoogled-chromium< 119.0.6045.159UNKNOWN
FreeBSDanynoarchqt5-webengine< 5.15.16.p5UNKNOWN
FreeBSDanynoarchqt6-webengine< 6.6.1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.002

Percentile

55.4%