PT-2023-1343 · Google+4 · Google Chrome+4

Sumin Hwang

·

Publicado

2023-02-07

·

Atualizado

2024-06-15

·

CVE-2023-0701

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 110.0.5481.77
Description The issue is related to a heap buffer overflow in the WebUI of Google Chrome, which could be exploited by a remote attacker who convinces a user to engage in specific UI interactions, potentially leading to heap corruption via UI interaction. This could allow an attacker to execute arbitrary code using a specially crafted HTML page.
Recommendations For versions prior to 110.0.5481.77, update to version 110.0.5481.77 or later to resolve the issue. As a temporary workaround, consider restricting user interactions with the WebUI to minimize the risk of exploitation.

Correção

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-1233
ALT-PU-2023-1245
ALT-PU-2023-1410
ALT-PU-2023-1462
ALT-PU-2023-1603
ALT-PU-2023-1671
BDU:2023-00652
CVE-2023-0701
DSA-5345-1
OPENSUSE-SU-2023:0045-1
OPENSUSE-SU-2023:0063-1
OPENSUSE-SU-2023:0115-1
OPENSUSE-SU-2023_0063-1
OPENSUSE-SU-2023_0115-1
OPENSUSE-SU-2024:12675-1
OPENSUSE-SU-2024:12948-1
USN-5881-1

Produtos afetados

Alt Linux
Astra Linux
Google Chrome
Suse
Ubuntu