Lucene search

K
freebsdFreeBSD7314942B-0889-46F0-B02B-2C60AABE4A82
HistoryApr 10, 2024 - 12:00 a.m.

chromium -- multiple security fixes

2024-04-1000:00:00
vuxml.freebsd.org
12
chrome
security fixes
out of bounds write
heap buffer overflow
use after free
compositing
angle
dawn

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%

Chrome Releases reports:

This update includes 3 security fixes:

[331237485] High CVE-2024-3157: Out of bounds write in Compositing. Reported by DarkNavy on 2024-03-26
[328859176] High CVE-2024-3516: Heap buffer overflow in ANGLE. Reported by Bao (zx) Pham and Toan (suto) Pham of Qrious Secure on 2024-03-09
[331123811] High CVE-2024-3515: Use after free in Dawn. Reported by wgslfuzz on 2024-03-25

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchchromium< 123.0.6312.122UNKNOWN
FreeBSDanynoarchungoogled-chromium< 123.0.6312.122UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.2 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

15.5%