Lucene search

K
freebsdFreeBSD7A42852D-0347-11EF-9F97-A8A1599412C6
HistoryApr 24, 2024 - 12:00 a.m.

chromium -- multiple security fixes

2024-04-2400:00:00
vuxml.freebsd.org
8
type confusion angle out of bounds read v8 api use after free dawn security fixes chromium chrome releases unix multiple

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.4%

Chrome Releases reports:

This update includes 4 security fixes:

[332546345] Critical CVE-2024-4058: Type Confusion in ANGLE. Reported by Toan (suto) Pham and Bao (zx) Pham of Qrious Secure on 2024-04-02
[333182464] High CVE-2024-4059: Out of bounds read in V8 API. Reported by Eirik on 2024-04-08
[333420620] High CVE-2024-4060: Use after free in Dawn. Reported by wgslfuzz on 2024-04-09

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchchromium< 124.0.6367.78UNKNOWN
FreeBSDanynoarchungoogled-chromium< 124.0.6367.78UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

7.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.4%