CVE-2022-2008
published 2022-07-28CVE-2022-2008: Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.85%
54.2th percentile
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 102.0.5005.115-1~deb11u1 | 102.0.5005.115-1~deb11u1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| chromium | chromium | >= 0 < 102.0.5005.115-1 | 102.0.5005.115-1 |
| debian | chromium | < chromium 102.0.5005.115-1 (bookworm) | chromium 102.0.5005.115-1 (bookworm) |
| fedoraproject | fedora | — | — |
| github.com | migueldeicaza_swiftterm | >= 0 < 1.2.0 | 1.2.0 |
| chrome | < 102.0.5005.115 | 102.0.5005.115 | |
| chrome | >= unspecified < 102.0.5005.115 | 102.0.5005.115 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
| msrc | remote_desktop_client | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_1909 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.3HIGH
osv8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
vendor_msrc·2022-06-14·CVSS 8.8
CVE-2022-2008 [HIGH] Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
Chromium: CVE-2022-2008 Out of bounds memory access in WebGL
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
102.0.1245.41
6/13/2022
102.0.5005.115
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Chrome
Stable Channel Update for Desktop: CVE-2022-2007
vendor_chrome·2022-06-09·CVSS 8.8
CVE-2022-2007 [HIGH] Stable Channel Update for Desktop: CVE-2022-2007
Stable Channel Update for Desktop
CVE-2022-2007: Use after free in WebGPU. Reported by David Manouchehri on 2022-05-17 [$TBD][ 1317673 ] High CVE-2022-2008: Out of bounds memory access in WebGL
Reported by khangkito - Tran Van Khang (VinCSS) on 2022-04-19 [$NA][ 1325298 ] High CVE-2022-2010: Out of bounds read in compositing
Severity: high
CISA
Adobe Reader and Acrobat Input Validation Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2008-2992 [HIGH] CWE-119 Adobe Reader and Acrobat Input Validation Vulnerability
Vulnerability: Adobe Reader and Acrobat Input Validation Vulnerability
Affected: Adobe Acrobat and Reader
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2008-2992
Remediation Due Date: 2022-03-24
CISA
Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-0001 [HIGH] Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Vulnerability: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
Affected: Microsoft Graphics Device Interface (GDI)
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0001
Remediation Due Date: 2022-03-24
CISA
Oracle VirtualBox Insufficient Input Validation Vulnerability
cisa·2022-03-03·CVSS 8.8
CVE-2008-3431 [HIGH] CWE-264 Oracle VirtualBox Insufficient Input Validation Vulnerability
Vulnerability: Oracle VirtualBox Insufficient Input Validation Vulnerability
Affected: Oracle VirtualBox
An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2008-3431
Remediation Due Date: 2022-03-24
CISA
Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
cisa·2022-03-03·CVSS 7.8
CVE-2017-8540 [HIGH] CWE-119 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Vulnerability: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability
Affected: Microsoft Malware Protection Engine
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-8540
Remediation Due Date: 2022-03-24
Debian
CVE-2022-2008: chromium - Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote a...
vendor_debian·2022·CVSS 8.8
CVE-2022-2008 [HIGH] CVE-2022-2008: chromium - Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote a...
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 102.0.5005.115-1)
bullseye: resolved (fixed in 102.0.5005.115-1~deb11u1)
forky: resolved (fixed in 102.0.5005.115-1)
sid: resolved (fixed in 102.0.5005.115-1)
trixie: resolved (fixed in 102.0.5005.115-1)
GHSA
SwiftTerm Code Injection vulnerability
ghsa·2023-07-14·CVSS 7.3
CVE-2022-23465 [HIGH] CWE-94 SwiftTerm Code Injection vulnerability
SwiftTerm Code Injection vulnerability
### Impact
Attacker could modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
### Credit
These bugs were found and disclosed by David Leadbeater (@dgl at Github.com)
### Patches
Fixed in version ce596e0dc8cdb288bc7ed5c6a59011ee3a8dc171
### Workarounds
There are no workarounds available
### References
Similar exploits to this existed in the past, for terminal emulators:
https://nvd.nist.gov/vuln/detail/CVE-2003-0063
https://nvd.nist.gov/vuln/detail/CVE-2008-2383
Additional background and information is also available:
https://marc.info
GHSA
GHSA-999f-6jgc-2cc6: Double free in WebGL in Google Chrome prior to 102
ghsa_unreviewed·2022-07-29
CVE-2022-2008 [HIGH] CWE-415 GHSA-999f-6jgc-2cc6: Double free in WebGL in Google Chrome prior to 102
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2022-2008: Double free in WebGL in Google Chrome prior to 102
osv·2022-07-28·CVSS 8.8
CVE-2022-2008 [HIGH] CVE-2022-2008: Double free in WebGL in Google Chrome prior to 102
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
Microsoft Critical and Important Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka flaws) in the June
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
- Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka fl
https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.htmlhttps://crbug.com/1317673https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop.htmlhttps://crbug.com/1317673https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4NMJURTG5RO3TGD7ZMIQ6Z4ZZ3SAVYE/
2022-07-28
Published