8.8

CVE-2023-7024

Warnung
Exploit
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Google ≫ Chrome Version < 120.0.6099.129
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Fedoraproject ≫ Fedora Version 38
Fedoraproject ≫ Fedora Version 39

02.01.2024: CISA Known Exploited Vulnerabilities (KEV) Catalog

Google Chromium WebRTC Heap Buffer Overflow Vulnerability

Schwachstelle

Google Chromium WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using WebRTC, including but not limited to Google Chrome.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.36% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://security.gentoo.org/glsa/202401-34
Third Party Advisory
https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html
Vendor Advisory
https://crbug.com/1513170
Exploit
Issue Tracking
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6M6AJDHUL6EDPURWQXGLUFJNDE7SOJT3/
Broken Link
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U6JL4VHZMHFGEGQYTF74533ZNRWMCMMR/
Broken Link
Mailing List
https://www.debian.org/security/2023/dsa-5585
Mailing List
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7024
US Government Resource