Lucene search

K
mageiaGentoo FoundationMGASA-2023-0044
HistoryFeb 15, 2023 - 1:43 a.m.

Updated chromium-browser-stable packages fix security vulnerability

2023-02-1501:43:23
Gentoo Foundation
advisories.mageia.org
15
chromium-browser-stable
109.0.5414.119
security fixes
cve-2023-0471
use after free
webtransport
chichoo kim
cassidy kim
kunlun lab
serviceworker api
type confusion
guestview
s.s.l.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.009 Low

EPSS

Percentile

83.0%

The chromium-browser-stable package has been updated to the 109.0.5414.119 release, fixing 6 vulnerabilities. Some of the security fixes are: High CVE-2023-0471: Use after free in WebTransport. Reported by chichoo Kim(chichoo) and Cassidy Kim(@cassidy6564) on 2022-10-19 High CVE-2023-0472: Use after free in WebRTC. Reported by Cassidy Kim(@cassidy6564) on 2023-01-06 Medium CVE-2023-0473: Type Confusion in ServiceWorker API. Reported by raven at KunLun lab on 2023-01-03 Medium CVE-2023-0474: Use after free in GuestView. Reported by avaue at S.S.L on 2022-12-14

OSVersionArchitecturePackageVersionFilename
Mageia8noarchchromium-browser-stable< 109.0.5414.119-1chromium-browser-stable-109.0.5414.119-1.mga8

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.009 Low

EPSS

Percentile

83.0%