Lucene search

K
freebsdFreeBSD502C9F72-99B3-11EE-86BB-A8A1599412C6
HistoryDec 12, 2023 - 12:00 a.m.

chromium -- multiple security fixes

2023-12-1200:00:00
vuxml.freebsd.org
22
chromium
security fixes
type confusion
use after free
v8
blink
libavif
webrtc
fedcm
css
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

41.8%

Chrome Releases reports:

This update includes 9 security fixes:

[1501326] High CVE-2023-6702: Type Confusion in V8. Reported by Zhiyi Zhang and Zhunki from Codesafe Team of Legendsec at Qi’anxin Group on 2023-11-10
[1502102] High CVE-2023-6703: Use after free in Blink. Reported by Cassidy Kim(@cassidy6564) on 2023-11-14
[1504792] High CVE-2023-6704: Use after free in libavif. Reported by Fudan University on 2023-11-23
[1505708] High CVE-2023-6705: Use after free in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2023-11-28
[1500921] High CVE-2023-6706: Use after free in FedCM. Reported by anonymous on 2023-11-09
[1504036] Medium CVE-2023-6707: Use after free in CSS. Reported by @ginggilBesel on 2023-11-21

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchchromium< 120.0.6099.109UNKNOWN
FreeBSDanynoarchungoogled-chromium< 120.0.6099.109UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

41.8%