CVE-2023-0700
published 2023-02-07CVE-2023-0700: Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox…
PriorityP430medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.68%
48.0th percentile
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 110.0.5481.77-1~deb11u1 | 110.0.5481.77-1~deb11u1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| chromium | chromium | >= 0 < 110.0.5481.77-1 | 110.0.5481.77-1 |
| debian | chromium | < chromium 110.0.5481.77-1 (bookworm) | chromium 110.0.5481.77-1 (bookworm) |
| github.com | minio_console | >= 0 < 0.28.0 | 0.28.0 |
| github.com | minio_minio | >= 0 < 0.0.0-202303200415 | 0.0.0-202303200415 |
| github.com | minio_minio | >= 0 < 0.0.0-202303200735 | 0.0.0-202303200735 |
| chrome | < 110.0.5481.77 | 110.0.5481.77 | |
| chrome | >= unspecified < 110.0.5481.77 | 110.0.5481.77 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_redhat7.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: powerpc/rtas_flash: allow user copy to flash block cache objects
vendor_redhat·2025-10-01·CVSS 7.8
CVE-2023-53487 [HIGH] CWE-276 kernel: powerpc/rtas_flash: allow user copy to flash block cache objects
kernel: powerpc/rtas_flash: allow user copy to flash block cache objects
In the Linux kernel, the following vulnerability has been resolved:
powerpc/rtas_flash: allow user copy to flash block cache objects
With hardened usercopy enabled (CONFIG_HARDENED_USERCOPY=y), using the
/proc/powerpc/rtas/firmware_update interface to prepare a system
firmware update yields a BUG():
kernel BUG at mm/usercopy.c:102!
Oops: Exception in kernel mode, sig: 5 [#1]
LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries
Modules linked in:
CPU: 0 PID: 2232 Comm: dd Not tainted 6.5.0-rc3+ #2
Hardware name: IBM,8408-E8E POWER8E (raw) 0x4b0201 0xf000004 of:IBM,FW860.50 (SV860_146) hv:phyp pSeries
NIP: c0000000005991d0 LR: c0000000005991cc CTR: 0000000000000000
REGS: c0000000148c76a0 TRAP: 0700 Not tainted (6.5.
Ubuntu
Chromium vulnerabilities
vendor_ubuntu·2023-02-21·CVSS 8.8
CVE-2023-0700 [HIGH] Chromium vulnerabilities
Title: Chromium vulnerabilities
Summary: Several security issues were fixed in Chromium.
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of
Microsoft
Chromium: CVE-2023-0700 Inappropriate implementation in Download
vendor_msrc·2023-02-14·CVSS 6.5
CVE-2023-0700 [MEDIUM] Chromium: CVE-2023-0700 Inappropriate implementation in Download
Chromium: CVE-2023-0700 Inappropriate implementation in Download
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft
Chrome
Stable Channel Update for Desktop: CVE-2023-0699
vendor_chrome·2023-02-07·CVSS 8.8
CVE-2023-0699 [MEDIUM] Stable Channel Update for Desktop: CVE-2023-0699
Stable Channel Update for Desktop
CVE-2023-0699: Use after free in GPU. Reported by 7o8v and Cassidy Kim(@cassidy6564) on 2022-10-06 [$3000][ 1393732 ] Medium CVE-2023-0700: Inappropriate implementation in Download
Reported by Axel Chong on 2022-11-26 [$2000][ 1405123 ] Medium CVE-2023-0701: Heap buffer overflow in WebUI
Severity: medium
Debian
CVE-2023-0700: chromium - Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77...
vendor_debian·2023·CVSS 6.5
CVE-2023-0700 [MEDIUM] CVE-2023-0700: chromium - Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77...
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 110.0.5481.77-1)
bullseye: resolved (fixed in 110.0.5481.77-1~deb11u1)
forky: resolved (fixed in 110.0.5481.77-1)
sid: resolved (fixed in 110.0.5481.77-1)
trixie: resolved (fixed in 110.0.5481.77-1)
GHSA
Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
ghsa·2023-09-06
CVE-2023-28433 [HIGH] CWE-668 Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
Minio vulnerable to Privilege Escalation on Windows via Path separator manipulation
### Impact
All users on Windows are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across
buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user.
### Patches
There are two patches that fix this problem comprehensively
```
commit b3c54ec81e0a06392abfb3a1ffcdc80c6fbf6ebc
Author: Harshavardhana
Date: Mon Mar 20 13:16:00 2023 -0700
reject object names with '\' on windows (#16856)
```
```
commit 8d6558b23649f613414c8527b58973fbdfa4d1b8
Author: Harshavardhana
Date: Mon Mar 20 00:35:25 2023 -0700
fix: convert '\' to '/' o
GHSA
Privilege Escalation on Linux/MacOS
ghsa·2023-09-05
CVE-2023-28434 [HIGH] CWE-269 Privilege Escalation on Linux/MacOS
Privilege Escalation on Linux/MacOS
### Impact
An attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access.
### Patches
```
commit 67f4ba154a27a1b06e48bfabda38355a010dfca5
Author: Aditya Manthramurthy
Date: Sun Mar 19 21:15:20 2023 -0700
fix: post policy request security bypass (#16849)
```
### Workarounds
Browser API access must be enabled turning off `MINIO_BROWSER=off` allows for this workaround.
### References
The vulnerable code:
```go
// minio/cmd/generic-handlers.go
func setRequestValidityHandler(h http.Handler) http.Handler {
return http.HandlerFunc(func(w http
GHSA
Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
ghsa·2023-05-26
CVE-2023-33955 [MEDIUM] CWE-200 Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
### Impact
Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename.
### Reported-By
Thanks to the report from Mio Li [[email protected]](mailto:[email protected])
### Patches
```
commit 17e791afb90c9ad27c65f63c6be14f2f6a3a9d60
Author: Daniel Valdivia
Date: Tue May 23 08:47:12 2023 -0700
Replace RIGHT-TO-LEFT OVERRIDE unicode (#2828)
Signed-off-by: Daniel Valdivia
```
### Workarounds
Workarounds are to remove the concerned file and rewrite it properly with the right file and extensions. Avoid using RTLO characters in your filenames.
OSV
chromium-browser vulnerabilities
osv·2023-02-21·CVSS 8.8
CVE-2023-0471 [HIGH] chromium-browser vulnerabilities
chromium-browser vulnerabilities
It was discovered that Chromium did not properly manage memory. A remote
attacker could possibly use these issues to cause a denial of service or
execute arbitrary code via a crafted HTML page. (CVE-2023-0471,
CVE-2023-0472, CVE-2023-0473, CVE-2023-0696, CVE-2023-0698, CVE-2023-0699,
CVE-2023-0702, CVE-2023-0705)
It was discovered that Chromium did not properly manage memory. A remote
attacker who convinced a user to install a malicious extension could
possibly use this issue to corrupt memory via a Chrome web app.
(CVE-2023-0474)
It was discovered that Chromium contained an inappropriate implementation
in the Download component. A remote attacker could possibly use this issue
to spoof contents of the Omnibox (URL bar) via a crafted HTML page.
(CVE-2023-
GHSA
GHSA-w634-6x8m-jgvx: Inappropriate implementation in Download in Google Chrome prior to 110
ghsa_unreviewed·2023-02-07
CVE-2023-0700 [MEDIUM] CWE-451 GHSA-w634-6x8m-jgvx: Inappropriate implementation in Download in Google Chrome prior to 110
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2023-0700: Inappropriate implementation in Download in Google Chrome prior to 110
osv·2023-02-07·CVSS 6.5
CVE-2023-0700 [MEDIUM] CVE-2023-0700: Inappropriate implementation in Download in Google Chrome prior to 110
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1393732https://security.gentoo.org/glsa/202309-17https://chromereleases.googleblog.com/2023/02/stable-channel-update-for-desktop.htmlhttps://crbug.com/1393732https://security.gentoo.org/glsa/202309-17
2023-02-07
Published