Alpine: multiple chromium packages: security update to 91.0.4472.77-r0

high Tenable Cloud Security Plugin ID 403824

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit
heap corruption via a crafted HTML page. (CVE-2021-30535)

- Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote
attacker to perform out of bounds memory access via a crafted HTML page. (CVE-2021-30521)

- Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-30522)

- Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit heap corruption via a crafted SCTP packet. (CVE-2021-30523)

- Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user
to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
(CVE-2021-30524)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-30521

https://security.alpinelinux.org/vuln/CVE-2021-30522

https://security.alpinelinux.org/vuln/CVE-2021-30523

https://security.alpinelinux.org/vuln/CVE-2021-30524

https://security.alpinelinux.org/vuln/CVE-2021-30525

https://security.alpinelinux.org/vuln/CVE-2021-30526

https://security.alpinelinux.org/vuln/CVE-2021-30527

https://security.alpinelinux.org/vuln/CVE-2021-30528

https://security.alpinelinux.org/vuln/CVE-2021-30529

https://security.alpinelinux.org/vuln/CVE-2021-30530

https://security.alpinelinux.org/vuln/CVE-2021-30531

https://security.alpinelinux.org/vuln/CVE-2021-30532

https://security.alpinelinux.org/vuln/CVE-2021-30533

https://security.alpinelinux.org/vuln/CVE-2021-30534

https://security.alpinelinux.org/vuln/CVE-2021-30535

https://security.alpinelinux.org/vuln/CVE-2021-30536

https://security.alpinelinux.org/vuln/CVE-2021-30537

https://security.alpinelinux.org/vuln/CVE-2021-30538

https://security.alpinelinux.org/vuln/CVE-2021-30539

https://security.alpinelinux.org/vuln/CVE-2021-30540

Plugin Details

Severity: High

ID: 403824

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-30535

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/25/2021

CISA Known Exploited Vulnerability Due Dates: 7/18/2022

Reference Information

CVE: CVE-2021-30521, CVE-2021-30522, CVE-2021-30523, CVE-2021-30524, CVE-2021-30525, CVE-2021-30526, CVE-2021-30527, CVE-2021-30528, CVE-2021-30529, CVE-2021-30530, CVE-2021-30531, CVE-2021-30532, CVE-2021-30533, CVE-2021-30534, CVE-2021-30535, CVE-2021-30536, CVE-2021-30537, CVE-2021-30538, CVE-2021-30539, CVE-2021-30540