Heap-based buffer overflow in Google Chromium - CVE-2023-44488,CVE-2023-5217

 

Heap-based buffer overflow in Google Chromium - CVE-2023-44488,CVE-2023-5217

Published: September 27, 2023 / Updated: May 13, 2024


Vulnerability identifier: #VU81244
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44488,CVE-2023-5217
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in vp8 encoding in libvpx. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Google Chromium
Firefox ESR
Microsoft Edge
Mozilla Firefox
Google Chrome
EcoStruxure Power Operation
Debian Linux
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Fedora
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
SUSE Linux Enterprise Workstation Extension 12
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Desktop Applications Module
Basesystem Module
SUSE Package Hub 15
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
openSUSE Leap
Apple iOS
iPadOS
openEuler
Chrome OS
Visual Studio Code
libvpx
VLC Media Player
RecoverPoint for VMs
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libvpx3 (Ubuntu package)
libvpx5 (Ubuntu package)
libvpx1 (Ubuntu package)
vpx-tools
libvpx1-32bit
vpx-tools-debuginfo
libvpx1-debuginfo-32bit
libvpx1-debuginfo
libvpx1
libvpx-debugsource
libvpx-devel
libvpx4-32bit-debuginfo
libvpx4
libvpx4-debuginfo
libvpx4-32bit
libvpx (Red Hat package)
libvpx-debuginfo
libvpx
libvpx-doc
libvpx6 (Ubuntu package)
libvpx (Debian package)
libvpx7 (Ubuntu package)
libvpx7-debuginfo
libvpx7
libvpx7-32bit-debuginfo
libvpx7-32bit
libvpx7-64bit-debuginfo
libvpx7-64bit
libvpx-utils
media-libs/libvpx
firefox
firefox-debuginfo
firefox-debugsource
mozilla-crashreporter-firefox-debuginfo
firefox-langpacks
firefox-x11
firefox-wayland
thunderbird (Ubuntu package)
mozilla-thunderbird
mozilla-firefox
firefox-esr (Debian package)
thunderbird (Red Hat package)
firefox (Red Hat package)
thunderbird
MozillaFirefox
MozillaFirefox-debugsource
MozillaFirefox-translations-common
MozillaFirefox-debuginfo
MozillaFirefox-devel
MozillaFirefox-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird-translations-other
MozillaThunderbird-translations-common
MozillaThunderbird-debugsource
MozillaThunderbird
MozillaFirefox-branding-upstream
chromium
chromium (Debian package)
firefox (Ubuntu package)
www-client/microsoft-edge
www-client/google-chrome
www-client/chromium
Cisco Jabber
Mozilla Thunderbird
Cisco Webex Meetings
Firefox for Android
Firefox Focus for Android
VMware Horizon Client
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs

How to mitigate CVE-2023-44488,CVE-2023-5217

Update to version 117.0.5938.132.

Google Chromium - update to 117.0.5938.132
EcoStruxure Power Operation - update to 2024 CU2
Visual Studio Code - update to 1.82.3
libvpx - update to 1.13.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
VLC Media Player - update to 3.0.19
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Firefox ESR - update to 115.3.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Apple iOS - addressed in versions 16.7.1 20H30, 17.0.3 21A360
iPadOS - addressed in versions 16.7.1, 17.0.3
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
Firefox for Android - update to 118.1.0
Microsoft Edge - addressed in versions 116.0.1938.98, 117.0.2045.47
Mozilla Firefox - update to 118.0.1
Google Chrome - update to 117.0.5938.132
Mozilla Thunderbird - update to 115.3.1
Firefox Focus for Android - update to 118.1.0
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libvpx3 (Ubuntu package) - update to Ubuntu Pro
libvpx5 (Ubuntu package) - update to Ubuntu Pro
libvpx1 (Ubuntu package) - update to 1.3.0-2ubuntu0.1~esm3
vpx-tools - addressed in versions 1.3.0-3.12.1, 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx1-32bit - update to 1.3.0-3.12.1
vpx-tools-debuginfo - addressed in versions 1.3.0-3.12.1, 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx1-debuginfo-32bit - update to 1.3.0-3.12.1
libvpx1-debuginfo - update to 1.3.0-3.12.1
libvpx1 - update to 1.3.0-3.12.1
libvpx-debugsource - addressed in versions 1.3.0-3.12.1, 1.6.1-150000.6.11.1, 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx-devel - addressed in versions 1.3.0-3.12.1, 1.6.1-150000.6.11.1, 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx4-32bit-debuginfo - update to 1.6.1-150000.6.11.1
libvpx4 - update to 1.6.1-150000.6.11.1
libvpx4-debuginfo - update to 1.6.1-150000.6.11.1
libvpx4-32bit - update to 1.6.1-150000.6.11.1
libvpx (Red Hat package) - addressed in versions 1.7.0-8.el8_1, 1.7.0-8.el8_2, 1.7.0-10.el8_4, 1.7.0-10.el8_6, 1.7.0-10.el8_8, 1.9.0-7.el9_0, 1.9.0-7.el9_2
libvpx-debugsource - update to 1.7.0-10
libvpx-debuginfo - update to 1.7.0-10
libvpx-devel - update to 1.7.0-10
libvpx - update to 1.7.0-10
libvpx - addressed in versions 1.7.0-10.0.1, 1.12.0-3
libvpx-devel - addressed in versions 1.7.0-10.0.1, 1.12.0-3
libvpx-doc - addressed in versions 1.7.0-10.0.1, 1.12.0-3
libvpx6 (Ubuntu package) - update to 1.8.2-1ubuntu0.2
libvpx (Debian package) - addressed in versions 1.9.0-1+deb11u1, 1.9.0-1+deb11u2, 1.12.0-1+deb12u1, 1.12.0-1+deb12u2
libvpx - update to 1.11.0-1
libvpx7 (Ubuntu package) - addressed in versions 1.11.0-2ubuntu2.2, 1.12.0-1ubuntu1.2
libvpx7-debuginfo - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx7 - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx7-32bit-debuginfo - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx7-32bit - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx7-64bit-debuginfo - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx7-64bit - addressed in versions 1.11.0-150400.3.3.1, 1.11.0-150400.3.7.1
libvpx - update to 1.12.0
libvpx-utils - update to 1.12.0-3
libvpx - addressed in versions 1.12.0-3.fc37, 1.13.0-5.fc38, 1.13.0-5.fc39
media-libs/libvpx - update to 1.13.1
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.3
Isolation Segment - addressed in versions 2.11.42, 2.13.27, 3.0.18, 3.0.20, 4.0.10, 4.0.12
VMware Tanzu Application Service for VMs - addressed in versions 2.11.48, 2.13.30, 3.0.18, 3.0.20, 4.0.10, 4.0.12
RecoverPoint for VMs - update to 6.0.SP1.P1
firefox - addressed in versions 79.0-14, 79.0-18
firefox-debuginfo - addressed in versions 79.0-14, 79.0-18
firefox-debugsource - addressed in versions 79.0-14, 79.0-18
mozilla-crashreporter-firefox-debuginfo - addressed in versions 79.0-14, 79.0-18
Chrome OS - update to 114.0.5735.337
firefox-langpacks - update to 115.3.0-1
firefox-x11 - update to 115.3.0-1
firefox - addressed in versions 115.3.0-1, 115.3.1-1.0.1, 115.4.0-1.0.1
firefox-wayland - update to 115.3.0-1
thunderbird (Ubuntu package) - addressed in versions 1:115.3.1+build1-0ubuntu0.20.04.1, 1:115.3.1+build1-0ubuntu0.22.04.2, 1:115.3.1+build1-0ubuntu0.23.04.1
mozilla-thunderbird - update to 115.3.1
mozilla-firefox - update to 115.3.1esr
firefox-esr (Debian package) - update to 115.3.1esr-1~deb11u1
thunderbird (Red Hat package) - addressed in versions 115.3.1-1.el7_9, 115.3.1-1.el8_1, 115.3.1-1.el8_2, 115.3.1-1.el8_4, 115.3.1-1.el8_6, 115.3.1-1.el8_8, 115.3.1-1.el9_0, 115.3.1-1.el9_2, 115.4.1-1.el8_1, 115.4.1-1.el8_2, 115.4.1-1.el8_4, 115.4.1-1.el8_6, 115.4.1-1.el8_8, 115.4.1-1.el9_0, 115.4.1-1.el9_2
firefox (Red Hat package) - addressed in versions 115.3.1-1.el7_9, 115.3.1-1.el8_1, 115.3.1-1.el8_2, 115.3.1-1.el8_4, 115.3.1-1.el8_6, 115.3.1-1.el8_8, 115.3.1-1.el9_0, 115.3.1-1.el9_2, 115.4.0-1.el7_9, 115.4.0-1.el8_1, 115.4.0-1.el8_2, 115.4.0-1.el8_4, 115.4.0-1.el8_6, 115.4.0-1.el8_8, 115.4.0-1.el9_0, 115.4.0-1.el9_2
thunderbird - update to 115.3.1-1.fc39
thunderbird - addressed in versions 115.3.1-1.0.1, 115.4.1-1.0.1
MozillaFirefox - addressed in versions 115.3.1-112.185.1, 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaFirefox-debugsource - addressed in versions 115.3.1-112.185.1, 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaFirefox-translations-common - addressed in versions 115.3.1-112.185.1, 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaFirefox-debuginfo - addressed in versions 115.3.1-112.185.1, 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaFirefox-devel - addressed in versions 115.3.1-112.185.1, 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaFirefox-translations-other - addressed in versions 115.3.1-150000.150.110.1, 115.3.1-150200.152.111.1
MozillaThunderbird-debuginfo - update to 115.3.1-150200.8.133.1
MozillaThunderbird-translations-other - update to 115.3.1-150200.8.133.1
MozillaThunderbird-translations-common - update to 115.3.1-150200.8.133.1
MozillaThunderbird-debugsource - update to 115.3.1-150200.8.133.1
MozillaThunderbird - update to 115.3.1-150200.8.133.1
MozillaFirefox-branding-upstream - update to 115.3.1-150200.152.111.1
chromium - addressed in versions 117.0.5938.132-1.el7, 117.0.5938.132-1.el8, 117.0.5938.132-1.el9, 117.0.5938.132-1.fc37, 117.0.5938.132-2.fc38, 117.0.5938.132-2.fc39
chromium (Debian package) - addressed in versions 117.0.5938.132-1~deb11u1, 117.0.5938.132-1~deb12u1
firefox (Ubuntu package) - addressed in versions 118.0.1+build1-0ubuntu0.20.04.1, 118.0.2+build2-0ubuntu0.20.04.1
firefox - update to 118.0.1-4.fc39
www-client/microsoft-edge - update to 120.0.2210.133
www-client/google-chrome - update to 120.0.6099.109
www-client/chromium - update to 120.0.6099.109

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins