Lucene search

K
mageiaGentoo FoundationMGASA-2022-0480
HistoryDec 24, 2022 - 12:14 p.m.

Updated chromium-browser-stable packages fix security vulnerability

2022-12-2412:14:14
Gentoo Foundation
advisories.mageia.org
66
chromium
browser
security vulnerability
update
fix
cve-2022-4436
cve-2022-4437
cve-2022-4438
cve-2022-4439
cve-2022-4440
use after free

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

79.7%

The chromium-browser-stable package has been updated to the 108.0.5359.124 release, fixing 8 vulnerabilities. Some of the security fixes are … High CVE-2022-4436: Use after free in Blink Media. Reported by Anonymous on 2022-11-15 High CVE-2022-4437: Use after free in Mojo IPC. Reported by koocola(@alo_cook) and Guang Gong of 360 Vulnerability Research Institute on 2022-11-30 High CVE-2022-4438: Use after free in Blink Frames. Reported by Anonymous on 2022-11-07 High CVE-2022-4439: Use after free in Aura. Reported by Anonymous on 2022-11-22 Medium CVE-2022-4440: Use after free in Profiles. Reported by Anonymous on 2022-11-09

OSVersionArchitecturePackageVersionFilename
Mageia8noarchchromium-browser-stable< 108.0.5359.124-1chromium-browser-stable-108.0.5359.124-1.mga8

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.007

Percentile

79.7%