Lucene search

K
freebsdFreeBSDA11E7DD1-BED4-11EE-BDD6-4CCC6ADDA413
HistoryJan 08, 2024 - 12:00 a.m.

qt5-webengine -- Multiple vulnerabilities

2024-01-0800:00:00
vuxml.freebsd.org
23
qt5
webengine
multiple vulnerabilities
qtwebengine-chromium
integer overflow
type confusion
heap buffer overflow
use after free
insufficient data validation
chromium

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.099

Percentile

95.0%

Qt qtwebengine-chromium repo reports:

Backports for 8 security bugs in Chromium:

[1505053] High CVE-2023-6345: Integer overflow in Skia
[1501326] High CVE-2023-6702: Type Confusion in V8
[1513170] High CVE-2023-7024: Heap buffer overflow in WebRTC
[1501798] High CVE-2024-0222: Use after free in ANGLE
[1505086] High CVE-2024-0224: Use after free in WebAudio
[1513379] High CVE-2024-0333: Insufficient data validation in Extensions
[1507412] High CVE-2024-0518: Type Confusion in V8
[1517354] High CVE-2024-0519: Out of bounds memory access in V8

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchqt5-webengine<Β 5.15.16.p5_4UNKNOWN

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.099

Percentile

95.0%