Lucene search

K
mageiaGentoo FoundationMGASA-2023-0016
HistoryJan 24, 2023 - 10:58 a.m.

Updated chromium-browser-stable packages fix security vulnerability

2023-01-2410:58:25
Gentoo Foundation
advisories.mageia.org
28
chromium-browser-stable
update
security vulnerability
cve-2023-0128
cve-2023-0129
cve-2023-0130
cve-2023-0131
cve-2023-0132
cve-2023-0133
cve-2023-0134
cve-2023-0135
cve-2023-0136
cve-2023-0137
cve-2023-0138
cve-2023-0139
cve-2023-0140
cve-2023-0141

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

74.3%

The chromium-browser-stable package has been updated to the 109.0.5414.74 release, fixing 17 vulnerabilities. Some of the security fixes are - High CVE-2023-0128 Use after free in Overview Mode. Reported by Khalil Zhani on 2022-08-16 High CVE-2023-0129 Heap buffer overflow in Network Service. Reported by asnine on 2022-11-07 Medium CVE-2023-0130 Inappropriate implementation in Fullscreen API. Reported by Hafiizh on 2022-09-30 Medium CVE-2023-0131 Inappropriate implementation in iframe Sandbox. Reported by NDevTK on 2022-08-28 Medium CVE-2023-0132 Inappropriate implementation in Permission prompts. Reported by Jasper Rebane (popstonia) on 2022-10-05 Medium CVE-2023-0133 Inappropriate implementation in Permission prompts. Reported by Alesandro Ortiz on 2022-10-17 Medium CVE-2023-0134 Use after free in Cart. Reported by Chaoyuan Peng (@ret2happy) on 2022-11-17 Medium CVE-2023-0135 Use after free in Cart. Reported by Chaoyuan Peng (@ret2happy) on 2022-11-18 Medium CVE-2023-0136 Inappropriate implementation in Fullscreen API. Reported by Axel Chong on 2022-08-26 Medium CVE-2023-0137 Heap buffer overflow in Platform Apps. Reported by avaue and Buff3tts at S.S.L. on 2022-12-10 Low CVE-2023-0138 Heap buffer overflow in libphonenumber. Reported by Michael Dau on 2022-07-23 Low CVE-2023-0139 Insufficient validation of untrusted input in Downloads. Reported by Axel Chong on 2022-09-24 Low CVE-2023-0140 Inappropriate implementation in File System API. Reported by harrison.mitchell, cybercx.com.au on 2022-05-18 Low CVE-2023-0141 Insufficient policy enforcement in CORS. Reported by scarlet on 2022-09-12

OSVersionArchitecturePackageVersionFilename
Mageia8noarchchromium-browser-stable< 109.0.5414.74-1chromium-browser-stable-109.0.5414.74-1.mga8

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.004 Low

EPSS

Percentile

74.3%