Lucene search

K
freebsdFreeBSDFD3401A1-B6DF-4577-917A-2C22FEE99D34
HistoryMar 05, 2024 - 12:00 a.m.

chromium -- multiple security fixes

2024-03-0500:00:00
vuxml.freebsd.org
22
chromium
update
high-severity
security fixes
v8
out of bounds memory access
inappropriate implementation
use after free
fedcm
cve-2024-2173
cve-2024-2174
cve-2024-2176
unix

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.5%

Chrome Releases reports:

This update includes 3 security fixes:

[325893559] High CVE-2024-2173: Out of bounds memory access in V8. Reported by 5fceb6172bbf7e2c5a948183b53565b9 on 2024-02-19
[325866363] High CVE-2024-2174: Inappropriate implementation in V8. Reported by 5f46f4ee2e17957ba7b39897fb376be8 on 2024-02-19
[325936438] High CVE-2024-2176: Use after free in FedCM. Reported by Anonymous on 2024-02-20

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchchromium< 122.0.6261.111UNKNOWN
FreeBSDanynoarchungoogled-chromium< 122.0.6261.111UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

15.5%