Heap-based buffer overflow in Google Chromium - CVE-2023-1220
Published: March 7, 2023 / Updated: March 8, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted HTML content in UMA. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Affected software
Microsoft Edge
Google Chrome
Debian Linux
Fedora
Ubuntu
Chrome OS
wf-recorder
neatvnc
loudgain
haruna
mpv
siril
alsa-plugins
stellarium
xine-lib
guacamole-server
chromaprint
celestia
retroarch
gstreamer1-plugin-libav
indi-3rdparty-libraries
indi-3rdparty-drivers
libindi
qmmp-plugin-pack
qmmp
attract-mode
phd2
notcurses
blender
kstars
audacious-plugins
kpipewire
ffmpeg
qt6-qtmultimedia
qt6-qtwebengine
unpaper
mlt
nv-codec-headers
k3b
ffmpegthumbs
chromium-browser (Ubuntu package)
chromium
chromium (Debian package)
How to mitigate CVE-2023-1220
Microsoft Edge - addressed in versions 110.0.1587.69, 111.0.1661.41
Google Chrome - update to 111.0.5563.64
wf-recorder - update to 0.3.1-0.3.20221225gita9725f7.fc38
neatvnc - update to 0.6.0-2.fc38
loudgain - update to 0.6.8-13.fc38
haruna - update to 0.10.3-3.fc38
mpv - update to 0.35.1-3.fc38
siril - update to 1.0.6-6.fc38
alsa-plugins - update to 1.2.7.1-5.fc38
stellarium - update to 1.2-8.fc38
xine-lib - update to 1.2.13-1.fc38
guacamole-server - update to 1.5.0-2.fc38
chromaprint - update to 1.5.1-8.fc38
celestia - update to 1.7.0~20230305ebfcdb1-4.fc38
retroarch - update to 1.15.0-4.fc38
gstreamer1-plugin-libav - update to 1.22.0-2.fc38
indi-3rdparty-libraries - update to 2.0.0-1.fc38
indi-3rdparty-drivers - update to 2.0.0-2.fc38
libindi - update to 2.0.0-3.fc38
qmmp-plugin-pack - update to 2.1.0-5.fc38
qmmp - update to 2.1.2-4.fc38
attract-mode - update to 2.6.2-6.fc38
phd2 - update to 2.6.11^dev4^20230212a205f63-1.fc38
notcurses - update to 3.0.8-6.fc38
blender - update to 3.4.1-16.fc38
kstars - update to 3.6.3-1.fc38
audacious-plugins - update to 4.3-2.fc38
kpipewire - update to 5.27.2-2.fc38
ffmpeg - update to 6.0-1.fc38
qt6-qtmultimedia - update to 6.4.2-4.fc38
qt6-qtwebengine - update to 6.4.2-4.fc38
unpaper - update to 7.0.0-7.fc38
mlt - update to 7.14.0-2.fc38
nv-codec-headers - update to 12.0.16.0-1.fc38
k3b - update to 22.12.3-2.fc38
ffmpegthumbs - update to 22.12.3-2.fc38
Chrome OS - update to 108.0.5359.224
chromium-browser (Ubuntu package) - update to 111.0.5563.64-0ubuntu0.18.04.5
chromium - addressed in versions 111.0.5563.64-1.el7, 111.0.5563.64-1.el8, 111.0.5563.64-1.el9, 111.0.5563.64-1.fc36, 111.0.5563.64-1.fc37, 111.0.5563.64-1.fc38, 111.0.5563.64-2.fc38
chromium (Debian package) - update to 111.0.5563.64-1~deb11u1
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Debian update for chromium
- Ubuntu update for chromium-browser
- Multiple vulnerabilities in Microsoft Edge
- Multiple vulnerabilities in Google ChromeOS LTS
- Fedora 38 update for chromium
- Fedora 37 update for chromium
- Fedora EPEL 7 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 36 update for chromium
- Fedora EPEL 9 update for chromium
- Fedora 38 update for alsa-plugins