Lucene search

K
ubuntuUbuntuUSN-5881-1
HistoryFeb 21, 2023 - 12:00 a.m.

Chromium vulnerabilities

2023-02-2100:00:00
ubuntu.com
43
chromium
ubuntu 18.04
memory management
denial of service
arbitrary code
remote attacker
crafted html page
chrome web app
omnibox
ui interactions
same origin policy
proxy settings

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.018

Percentile

88.4%

Releases

  • Ubuntu 18.04 ESM

Packages

  • chromium-browser - Chromium web browser, open-source version of Chrome

Details

It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)

It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)

It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of the Omnibox (URL bar) via a crafted HTML page.
(CVE-2023-0700)

It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to engage in specific UI interactions could
possibly use these issues to cause a denial of service or execute
arbitrary code. (CVE-2023-0701, CVE-2023-0703)

It was discovered that Chromium insufficiently enforced policies. A remote
attacker could possibly use this issue to bypass same origin policy and
proxy settings via a crafted HTML page. (CVE-2023-0704)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchchromium-browser< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-browser-dbgsym< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-browser-l10n< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-chromedriver< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-dbgsym< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-extra< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-extra-dbgsym< 110.0.5481.100-0ubuntu0.18.04.1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.018

Percentile

88.4%