Alpine: qt5-qtwebengine: security update to 5.15.3_git20220121-r4

critical Tenable Cloud Security Plugin ID 406852

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with
a nonzero XML_CONTEXT_BYTES. (CVE-2022-23852)

- Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker
to potentially exploit heap corruption via a crafted HTML page. (CVE-2022-0100)

- Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2022-0102)

- Use after free in SwiftShader in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (CVE-2022-0103)

- Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (CVE-2022-0104)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-0100

https://security.alpinelinux.org/vuln/CVE-2022-0102

https://security.alpinelinux.org/vuln/CVE-2022-0103

https://security.alpinelinux.org/vuln/CVE-2022-0104

https://security.alpinelinux.org/vuln/CVE-2022-0108

https://security.alpinelinux.org/vuln/CVE-2022-0109

https://security.alpinelinux.org/vuln/CVE-2022-0111

https://security.alpinelinux.org/vuln/CVE-2022-0113

https://security.alpinelinux.org/vuln/CVE-2022-0116

https://security.alpinelinux.org/vuln/CVE-2022-0117

https://security.alpinelinux.org/vuln/CVE-2022-0289

https://security.alpinelinux.org/vuln/CVE-2022-0291

https://security.alpinelinux.org/vuln/CVE-2022-0293

https://security.alpinelinux.org/vuln/CVE-2022-0298

https://security.alpinelinux.org/vuln/CVE-2022-0305

https://security.alpinelinux.org/vuln/CVE-2022-0306

https://security.alpinelinux.org/vuln/CVE-2022-0310

https://security.alpinelinux.org/vuln/CVE-2022-0456

https://security.alpinelinux.org/vuln/CVE-2022-0459

https://security.alpinelinux.org/vuln/CVE-2022-0460

https://security.alpinelinux.org/vuln/CVE-2022-0461

https://security.alpinelinux.org/vuln/CVE-2022-0606

https://security.alpinelinux.org/vuln/CVE-2022-0607

https://security.alpinelinux.org/vuln/CVE-2022-0608

https://security.alpinelinux.org/vuln/CVE-2022-0609

https://security.alpinelinux.org/vuln/CVE-2022-0610

https://security.alpinelinux.org/vuln/CVE-2022-23852

Plugin Details

Severity: Critical

ID: 406852

Version: Revision 1.34

Type: Local

Published: 10/31/2023

Updated: 6/1/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-23852

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 1/4/2022

CISA Known Exploited Vulnerability Due Dates: 3/1/2022

Reference Information

CVE: CVE-2022-0100, CVE-2022-0102, CVE-2022-0103, CVE-2022-0104, CVE-2022-0108, CVE-2022-0109, CVE-2022-0111, CVE-2022-0113, CVE-2022-0116, CVE-2022-0117, CVE-2022-0289, CVE-2022-0291, CVE-2022-0293, CVE-2022-0298, CVE-2022-0305, CVE-2022-0306, CVE-2022-0310, CVE-2022-0456, CVE-2022-0459, CVE-2022-0460, CVE-2022-0461, CVE-2022-0606, CVE-2022-0607, CVE-2022-0608, CVE-2022-0609, CVE-2022-0610, CVE-2022-23852