ALT-BU-2022-5645-1
Branch p10 update bulletin.
Closed vulnerabilities
BDU:2021-06407
Уязвимость пакета dnsproxy диспетчера соединений Connman, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код
BDU:2022-03145
Уязвимость пакета dnsproxy диспетчера соединений Connman, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию
BDU:2022-03146
Уязвимость пакета dnsproxy диспетчера соединений Connman, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
BDU:2022-03147
Уязвимость пакета dnsproxy диспетчера соединений Connman, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-33833
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).
- [oss-security] 20210609 connman stack buffer overflow in dnsproxy CVE-2021-33833
- [oss-security] 20210609 connman stack buffer overflow in dnsproxy CVE-2021-33833
- [oss-security] 20220125 Multiple vulnerabilities in connman's dnsproxy component
- [oss-security] 20220125 Multiple vulnerabilities in connman's dnsproxy component
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- https://lore.kernel.org/connman/
- https://lore.kernel.org/connman/
- GLSA-202107-29
- GLSA-202107-29
Modified: 2024-11-21
CVE-2022-23096
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- GLSA-202310-21
- GLSA-202310-21
- DSA-5231
- DSA-5231
- https://www.openwall.com/lists/oss-security/2022/01/25/1
- https://www.openwall.com/lists/oss-security/2022/01/25/1
Modified: 2024-11-21
CVE-2022-23097
An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- GLSA-202310-21
- GLSA-202310-21
- DSA-5231
- DSA-5231
- https://www.openwall.com/lists/oss-security/2022/01/25/1
- https://www.openwall.com/lists/oss-security/2022/01/25/1
Modified: 2024-11-21
CVE-2022-23098
An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- https://git.kernel.org/pub/scm/network/connman/connman.git/log/
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- [debian-lts-announce] 20220209 [SECURITY] [DLA 2915-1] connman security update
- GLSA-202310-21
- GLSA-202310-21
- DSA-5231
- DSA-5231
- https://www.openwall.com/lists/oss-security/2022/01/25/1
- https://www.openwall.com/lists/oss-security/2022/01/25/1
Closed vulnerabilities
BDU:2022-03500
Уязвимость компонента Compositing браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-03501
Уязвимость API для работы с компьютерной графикой WebGPU браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-03502
Уязвимость библиотеки ANGLE браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-03503
Уязвимость компонента WebGL браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
BDU:2022-03731
Уязвимость интерфейса File System API браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю обойти введенные ограничения безопасности с помощью специально созданного веб-сайта
BDU:2022-03732
Уязвимость браузеров Google Chrome и Microsoft Edge, существующая из-за недостаточной проверки входных данных при форматировании URL-адресов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2022-03733
Уязвимость компонента Extensions API браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2022-03734
Уязвимость компонента WebApp Provider браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
BDU:2022-03735
Уязвимость набора инструментов для веб-разработки DevTools браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю обойти существующие ограничения доступа
BDU:2022-03736
Уязвимость обработчика JavaScript-сценариев V8 браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код
BDU:2022-03737
Уязвимость реализации расширения «Группы вкладок» браузеров Google Chrome и Microsoft Edge, позволяющая нарушителю выполнить произвольный код
BDU:2022-03747
Уязвимость компонента Base браузеров Google Chrome и Microsoft, позволяющая нарушителю выполнить произвольный код
BDU:2022-04787
Уязвимость компонента WebGL веб-браузера Google Chrome, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2024-11-21
CVE-2022-2007
Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Modified: 2024-11-21
CVE-2022-2008
Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Modified: 2024-11-21
CVE-2022-2010
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Modified: 2024-11-21
CVE-2022-2011
Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Modified: 2024-11-21
CVE-2022-2156
Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1335458
- https://crbug.com/1335458
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2157
Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1327312
- https://crbug.com/1327312
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2158
Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1321078
- https://crbug.com/1321078
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2160
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1116450
- https://crbug.com/1116450
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2161
Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1330289
- https://crbug.com/1330289
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2162
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1307930
- https://crbug.com/1307930
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2163
Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.
- https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop_19.html
- https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop_19.html
- https://crbug.com/1308341
- https://crbug.com/1308341
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
- GLSA-202208-35
- GLSA-202208-35
Modified: 2024-11-21
CVE-2022-2164
Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1268445
- https://crbug.com/1268445
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2165
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1250993
- https://crbug.com/1250993
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-0102ccc2a2
- FEDORA-2022-1d3d5a0341
- FEDORA-2022-1d3d5a0341
- GLSA-202208-25
- GLSA-202208-25
Modified: 2024-11-21
CVE-2022-2415
Heap buffer overflow in WebGL in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- http://packetstormsecurity.com/files/167972/Chrome-WebGL-Uniform-Integer-Overflows.html
- http://packetstormsecurity.com/files/167972/Chrome-WebGL-Uniform-Integer-Overflows.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://chromereleases.googleblog.com/2022/06/stable-channel-update-for-desktop_21.html
- https://crbug.com/1316368
- https://crbug.com/1316368