CVE-2023-3598
published 2023-07-28CVE-2023-3598: Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted…
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.67%
48.2th percentile
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 114.0.5735.90-2~deb11u1 | 114.0.5735.90-2~deb11u1 |
| chromium | chromium | >= 0 < 114.0.5735.90-2~deb12u1 | 114.0.5735.90-2~deb12u1 |
| chromium | chromium | >= 0 < 114.0.5735.90-1 | 114.0.5735.90-1 |
| chromium | chromium | >= 0 < 114.0.5735.90-1 | 114.0.5735.90-1 |
| debian | chromium | < chromium 114.0.5735.90-2~deb12u1 (bookworm) | chromium 114.0.5735.90-2~deb12u1 (bookworm) |
| chrome | < 114.0.5735.90 | 114.0.5735.90 | |
| chrome | >= 114.0.5735.90 < 114.0.5735.90 | 114.0.5735.90 | |
| chrome_chrome | — | — | |
| juniper | junos_os | — | — |
| juniper | mx_series | — | — |
| juniper | srx_series | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Juniper
CVE-2023-28985: An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and
vendor_juniper·2023-07-14·CVSS 7.5
CVE-2023-28985 [HIGH] CWE-1286 CVE-2023-28985: An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and
CVE-2023-28985: An Improper Validation of Syntactic Correctness of Input vulnerability in Intrusion Detection and Prevention (IDP) of Juniper Networks SRX Series and MX Series allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). Continued receipt of this specific packet will cause a sustained Denial of Service condition.
On all SRX Series and MX Series platforms, where IDP is enabled and a specific malformed SSL packet is received, the SSL detector crashes leading to an FPC core.
This issue affects Juniper Networks SRX Series and MX Series prior to SigPack 3598.
In order to identify the current SigPack version, following command can be used:
user@junos# show security idp security-package-version
Chrome
Stable Channel Update for Desktop: CVE-2023-2929
vendor_chrome·2023-05-30·CVSS 8.8
CVE-2023-2929 [HIGH] Stable Channel Update for Desktop: CVE-2023-2929
Stable Channel Update for Desktop
CVE-2023-2929: Out of bounds write in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-25 [$10000][ 1443401 ] High CVE-2023-2930: Use after free in Extensions
Reported by asnine on 2023-05-08 [$10000][ 1427865 ] High CVE-2023-3598: Out of bounds read and write in ANGLE
Severity: high
Debian
CVE-2023-3598: chromium - Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 al...
vendor_debian·2023·CVSS 8.8
CVE-2023-3598 [HIGH] CVE-2023-3598: chromium - Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 al...
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 114.0.5735.90-2~deb12u1)
bullseye: resolved (fixed in 114.0.5735.90-2~deb11u1)
forky: resolved (fixed in 114.0.5735.90-1)
sid: resolved (fixed in 114.0.5735.90-1)
trixie: resolved (fixed in 114.0.5735.90-1)
GHSA
GHSA-g83q-4qw8-c6vg: Out of bounds read and write in ANGLE in Google Chrome prior to 114
ghsa_unreviewed·2023-07-28
CVE-2023-3598 [HIGH] CWE-787 GHSA-g83q-4qw8-c6vg: Out of bounds read and write in ANGLE in Google Chrome prior to 114
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2023-3598: Out of bounds read and write in ANGLE in Google Chrome prior to 114
osv·2023-07-28·CVSS 8.8
CVE-2023-3598 [HIGH] CVE-2023-3598: Out of bounds read and write in ANGLE in Google Chrome prior to 114
Out of bounds read and write in ANGLE in Google Chrome prior to 114.0.5735.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
bugzilla·2023-12-23·CVSS 8.8
CVE-2023-7090 [HIGH] CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
CVE-2023-7090 sudo: Improper handling of ipa_hostname leads to privilege mismanagement
A flaw was found in sudo in the handling of ipa_hostname, where ipa_hostname from /etc/sssd/sssd.conf was not propagated in sudo. Therefore, it leads to privilege mismanagement vulnerability in applications, where client hosts retain privileges even after retracting them.
Upstream Patch:
https://github.com/sudo-project/sudo/commit/e99082e05b9f0dd0e0f47fa1d2e1b9d922ea8c4c
https://www.sudo.ws/repos/sudo/rev/b4f31dbe3109
Upstream release:
https://www.sudo.ws/releases/legacy/#1.8.28
Red Hat Advisory:
https://access.redhat.com/errata/RHBA-2019:3598
References:
https://sudo.ws/pipermail/sudo-workers/2019-August/001248.html
https://sudo.ws/pipermail/sudo-workers/2019-August/001249.html
Bugzilla
CVE-2022-3598 libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c
bugzilla·2022-11-15·CVSS 6.5
CVE-2022-3598 [MEDIUM] CVE-2022-3598 libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c
CVE-2022-3598 libtiff: out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c
LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit cfbb883b.
References:
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-3598.json
https://gitlab.com/libtiff/libtiff/-/issues/435
https://gitlab.com/libtiff/libtiff/-/commit/cfbb883bf6ea7bedcb04177cc4e52d304522fdff
Discussion:
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 2148881]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2023:2340 https://a
https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/1427865https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/https://chromereleases.googleblog.com/2023/05/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/1427865https://lists.fedoraproject.org/archives/list/[email protected]/message/2LE64KGGOISKPKMYROSDT4K6QFVDIRF6/https://lists.fedoraproject.org/archives/list/[email protected]/message/B6SAST6CB5KKCQKH75ER2UQ3ICYPHCIZ/
2023-07-28
Published