Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 905297 (CVE-2023-21720, CVE-2023-21794, CVE-2023-23374, CVE-2023-28261, CVE-2023-28286, CVE-2023-29334) - <www-client/microsoft-edge-112.0.1722.48: multiple vulnerabilities
Summary: <www-client/microsoft-edge-112.0.1722.48: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2023-21720, CVE-2023-21794, CVE-2023-23374, CVE-2023-28261, CVE-2023-28286, CVE-2023-29334
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A2 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2023-04-29 16:52 UTC by John Helmert III
Modified: 2023-09-30 09:00 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-04-29 16:52:49 UTC
CVE-2023-29334 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29334):

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2023-28261 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28261):

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2023-28286 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-28286):

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2023-23374 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23374):

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

CVE-2023-21720 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21720):

Microsoft Edge (Chromium-based) Tampering Vulnerability

CVE-2023-21794 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21794):

Microsoft Edge (Chromium-based) Spoofing Vulnerability
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-05-31 04:27:59 UTC
Added to existing chrom* GLSA
Comment 2 Larry the Git Cow gentoo-dev 2023-09-30 08:57:36 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=de793de405f9e13d0d29d94de3f236ce0b5b3338

commit de793de405f9e13d0d29d94de3f236ce0b5b3338
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-09-30 08:56:23 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2023-09-30 08:57:27 +0000

    [ GLSA 202309-17 ] Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/893660
    Bug: https://bugs.gentoo.org/904252
    Bug: https://bugs.gentoo.org/904394
    Bug: https://bugs.gentoo.org/904560
    Bug: https://bugs.gentoo.org/905297
    Bug: https://bugs.gentoo.org/905620
    Bug: https://bugs.gentoo.org/905883
    Bug: https://bugs.gentoo.org/906586
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202309-17.xml | 152 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 152 insertions(+)