Lucene search

K
freebsdFreeBSD66907DAB-6BB2-11EF-B813-4CCC6ADDA413
HistoryAug 05, 2024 - 12:00 a.m.

qt5-webengine -- Multiple vulnerabilities

2024-08-0500:00:00
vuxml.freebsd.org
4
qt5-webengine
multiple vulnerabilities
backports
chromium
cve-2024-5496
cve-2024-5846
cve-2024-6291
cve-2024-6989
cve-2024-6996
cve-2024-7536
media session
pdfium
swiftshader
loader
race in frames
webaudio
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low

Backports for 6 security bugs in Chromium:

CVE-2024-5496: Use after free in Media Session
CVE-2024-5846: Use after free in PDFium
CVE-2024-6291: Use after free in Swiftshader
CVE-2024-6989: Use after free in Loader
CVE-2024-6996: Race in Frames
CVE-2024-7536: Use after free in WebAudio

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchqt5-webengine< 5.15.17.p3UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

Low