Alpine: multiple qt5-qtwebengine packages: security update to 5.15.3_git20211006-r0

critical Tenable Cloud Security Plugin ID 406840

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had
compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2021-30633)

- Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-30522)

- Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit heap corruption via a crafted SCTP packet. (CVE-2021-30523)

- Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker
to perform out of bounds memory access via a crafted HTML page. (CVE-2021-30530)

- Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote
attacker to bypass navigation restrictions via a crafted iframe. (CVE-2021-30533)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-30522

https://security.alpinelinux.org/vuln/CVE-2021-30523

https://security.alpinelinux.org/vuln/CVE-2021-30530

https://security.alpinelinux.org/vuln/CVE-2021-30533

https://security.alpinelinux.org/vuln/CVE-2021-30534

https://security.alpinelinux.org/vuln/CVE-2021-30535

https://security.alpinelinux.org/vuln/CVE-2021-30536

https://security.alpinelinux.org/vuln/CVE-2021-30541

https://security.alpinelinux.org/vuln/CVE-2021-30544

https://security.alpinelinux.org/vuln/CVE-2021-30547

https://security.alpinelinux.org/vuln/CVE-2021-30548

https://security.alpinelinux.org/vuln/CVE-2021-30551

https://security.alpinelinux.org/vuln/CVE-2021-30553

https://security.alpinelinux.org/vuln/CVE-2021-30554

https://security.alpinelinux.org/vuln/CVE-2021-30556

https://security.alpinelinux.org/vuln/CVE-2021-30559

https://security.alpinelinux.org/vuln/CVE-2021-30560

https://security.alpinelinux.org/vuln/CVE-2021-30563

https://security.alpinelinux.org/vuln/CVE-2021-30566

https://security.alpinelinux.org/vuln/CVE-2021-30568

https://security.alpinelinux.org/vuln/CVE-2021-30569

https://security.alpinelinux.org/vuln/CVE-2021-30573

https://security.alpinelinux.org/vuln/CVE-2021-30585

https://security.alpinelinux.org/vuln/CVE-2021-30587

https://security.alpinelinux.org/vuln/CVE-2021-30588

https://security.alpinelinux.org/vuln/CVE-2021-30598

https://security.alpinelinux.org/vuln/CVE-2021-30599

https://security.alpinelinux.org/vuln/CVE-2021-30602

https://security.alpinelinux.org/vuln/CVE-2021-30603

https://security.alpinelinux.org/vuln/CVE-2021-30604

https://security.alpinelinux.org/vuln/CVE-2021-30613

https://security.alpinelinux.org/vuln/CVE-2021-30618

https://security.alpinelinux.org/vuln/CVE-2021-30625

https://security.alpinelinux.org/vuln/CVE-2021-30626

https://security.alpinelinux.org/vuln/CVE-2021-30627

https://security.alpinelinux.org/vuln/CVE-2021-30628

https://security.alpinelinux.org/vuln/CVE-2021-30629

https://security.alpinelinux.org/vuln/CVE-2021-30633

Plugin Details

Severity: Critical

ID: 406840

Version: Revision 1.35

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-30633

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/25/2021

CISA Known Exploited Vulnerability Due Dates: 11/17/2021, 7/18/2022

Reference Information

CVE: CVE-2021-30522, CVE-2021-30523, CVE-2021-30530, CVE-2021-30533, CVE-2021-30534, CVE-2021-30535, CVE-2021-30536, CVE-2021-30541, CVE-2021-30544, CVE-2021-30547, CVE-2021-30548, CVE-2021-30551, CVE-2021-30553, CVE-2021-30554, CVE-2021-30556, CVE-2021-30559, CVE-2021-30560, CVE-2021-30563, CVE-2021-30566, CVE-2021-30568, CVE-2021-30569, CVE-2021-30573, CVE-2021-30585, CVE-2021-30587, CVE-2021-30588, CVE-2021-30598, CVE-2021-30599, CVE-2021-30602, CVE-2021-30603, CVE-2021-30604, CVE-2021-30613, CVE-2021-30618, CVE-2021-30625, CVE-2021-30626, CVE-2021-30627, CVE-2021-30628, CVE-2021-30629, CVE-2021-30633