Lucene search

K
ubuntuUbuntuUSN-5949-1
HistoryMar 13, 2023 - 12:00 a.m.

Chromium vulnerabilities

2023-03-1300:00:00
ubuntu.com
34
chromium
ubuntu
memory corruption
code execution
denial of service
html page
pdf file
policies enforcement
remote attacker
content security policy
resource timing
internals spoofing
navigation restrictions

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.2%

Releases

  • Ubuntu 18.04 ESM

Packages

  • chromium-browser - Chromium web browser, open-source version of Chrome

Details

It was discovered that Chromium could be made to write out of bounds in
several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-0930, CVE-2023-1219,
CVE-2023-1220, CVE-2023-1222)

It was discovered that Chromium contained an integer overflow in the PDF
component. A remote attacker could possibly use this issue to corrupt
memory via a crafted PDF file, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0933)

It was discovered that Chromium did not properly manage memory in several
components. A remote attacker could possibly use this issue to corrupt
memory via a crafted HTML page, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2023-0941, CVE-2023-0928,
CVE-2023-0929, CVE-2023-0931, CVE-2023-1213, CVE-2023-1216, CVE-2023-1218)

It was discovered that Chromium did not correctly distinguish data types
in several components. A remote attacker could possibly use this issue to
corrupt memory via a crafted HTML page, resulting in a denial of service,
or possibly execute arbitrary code. (CVE-2023-1214, CVE-2023-1215,
CVE-2023-1235)

It was discovered that Chromium insufficiently enforced policies. An
attacker could possibly use this issue to bypass navigation restrictions.
(CVE-2023-1221, CVE-2023-1224)

It was discovered that Chromium insufficiently enforced policies in Web
Payments API. A remote attacker could possibly use this issue to bypass
content security policy via a crafted HTML page. (CVE-2023-1226)

It was discovered that Chromium contained an inappropriate implementation
in the Permission prompts component. A remote attacker could possibly use
this issue to bypass navigation restrictions via a crafted HTML page.
(CVE-2023-1229)

It was discovered that Chromium insufficiently enforced policies in
Resource Timing component. A remote attacker could possibly use this issue
to obtain sensitive information. (CVE-2023-1232, CVE-2023-1233)

It was discovered that Chromium contained an inappropriate implementation
in the Internals component. A remote attacker could possibly use this
issue to spoof the origin of an iframe via a crafted HTML page.
(CVE-2023-1236)

OSVersionArchitecturePackageVersionFilename
Ubuntu18.04noarchchromium-browser< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-browser-dbgsym< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-browser-l10n< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-chromedriver< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-dbgsym< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-extra< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN
Ubuntu18.04noarchchromium-codecs-ffmpeg-extra-dbgsym< 111.0.5563.64-0ubuntu0.18.04.5UNKNOWN

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

8.6 High

AI Score

Confidence

Low

0.015 Low

EPSS

Percentile

87.2%