Use-after-free in Google Chromium - CVE-2023-1216

 

Use-after-free in Google Chromium - CVE-2023-1216

Published: March 7, 2023 / Updated: March 8, 2023


Vulnerability identifier: #VU73121
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1216
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the DevTools component in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it, trigger use-after-free error and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Debian Linux
Fedora
Ubuntu
wf-recorder
neatvnc
loudgain
haruna
mpv
siril
alsa-plugins
stellarium
xine-lib
guacamole-server
chromaprint
celestia
retroarch
gstreamer1-plugin-libav
indi-3rdparty-libraries
indi-3rdparty-drivers
libindi
qmmp-plugin-pack
qmmp
attract-mode
phd2
notcurses
blender
kstars
audacious-plugins
kpipewire
ffmpeg
qt6-qtwebengine
qt6-qtmultimedia
unpaper
mlt
nv-codec-headers
k3b
ffmpegthumbs
chromium-browser (Ubuntu package)
chromium
chromium (Debian package)

How to mitigate CVE-2023-1216

Update to version 111.0.5563.64.

Google Chromium - update to 111.0.5563.64
Microsoft Edge - addressed in versions 110.0.1587.69, 111.0.1661.41
Google Chrome - update to 111.0.5563.64
wf-recorder - update to 0.3.1-0.3.20221225gita9725f7.fc38
neatvnc - update to 0.6.0-2.fc38
loudgain - update to 0.6.8-13.fc38
haruna - update to 0.10.3-3.fc38
mpv - update to 0.35.1-3.fc38
siril - update to 1.0.6-6.fc38
alsa-plugins - update to 1.2.7.1-5.fc38
stellarium - update to 1.2-8.fc38
xine-lib - update to 1.2.13-1.fc38
guacamole-server - update to 1.5.0-2.fc38
chromaprint - update to 1.5.1-8.fc38
celestia - update to 1.7.0~20230305ebfcdb1-4.fc38
retroarch - update to 1.15.0-4.fc38
gstreamer1-plugin-libav - update to 1.22.0-2.fc38
indi-3rdparty-libraries - update to 2.0.0-1.fc38
indi-3rdparty-drivers - update to 2.0.0-2.fc38
libindi - update to 2.0.0-3.fc38
qmmp-plugin-pack - update to 2.1.0-5.fc38
qmmp - update to 2.1.2-4.fc38
attract-mode - update to 2.6.2-6.fc38
phd2 - update to 2.6.11^dev4^20230212a205f63-1.fc38
notcurses - update to 3.0.8-6.fc38
blender - update to 3.4.1-16.fc38
kstars - update to 3.6.3-1.fc38
audacious-plugins - update to 4.3-2.fc38
kpipewire - update to 5.27.2-2.fc38
ffmpeg - update to 6.0-1.fc38
qt6-qtwebengine - update to 6.4.2-4.fc38
qt6-qtmultimedia - update to 6.4.2-4.fc38
unpaper - update to 7.0.0-7.fc38
mlt - update to 7.14.0-2.fc38
nv-codec-headers - update to 12.0.16.0-1.fc38
k3b - update to 22.12.3-2.fc38
ffmpegthumbs - update to 22.12.3-2.fc38
chromium-browser (Ubuntu package) - update to 111.0.5563.64-0ubuntu0.18.04.5
chromium - addressed in versions 111.0.5563.64-1.el7, 111.0.5563.64-1.el8, 111.0.5563.64-1.el9, 111.0.5563.64-1.fc36, 111.0.5563.64-1.fc37, 111.0.5563.64-1.fc38, 111.0.5563.64-2.fc38
chromium (Debian package) - update to 111.0.5563.64-1~deb11u1

External References

Related Security Bulletins