Alpine: qt5-qtwebengine: security update to 5.15.3_git20210510-r0

critical Tenable Self-Hosted Container Security Plugin ID 406833

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker
to potentially exploit heap corruption via a crafted HTML page. (CVE-2021-21233)

- Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had
compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2021-21201)

- Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a
user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome
Extension. (CVE-2021-21202)

- Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-21203)

- Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (CVE-2021-21204)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-21201

https://security.alpinelinux.org/vuln/CVE-2021-21202

https://security.alpinelinux.org/vuln/CVE-2021-21203

https://security.alpinelinux.org/vuln/CVE-2021-21204

https://security.alpinelinux.org/vuln/CVE-2021-21206

https://security.alpinelinux.org/vuln/CVE-2021-21207

https://security.alpinelinux.org/vuln/CVE-2021-21209

https://security.alpinelinux.org/vuln/CVE-2021-21213

https://security.alpinelinux.org/vuln/CVE-2021-21214

https://security.alpinelinux.org/vuln/CVE-2021-21217

https://security.alpinelinux.org/vuln/CVE-2021-21219

https://security.alpinelinux.org/vuln/CVE-2021-21220

https://security.alpinelinux.org/vuln/CVE-2021-21221

https://security.alpinelinux.org/vuln/CVE-2021-21222

https://security.alpinelinux.org/vuln/CVE-2021-21223

https://security.alpinelinux.org/vuln/CVE-2021-21224

https://security.alpinelinux.org/vuln/CVE-2021-21225

https://security.alpinelinux.org/vuln/CVE-2021-21227

https://security.alpinelinux.org/vuln/CVE-2021-21230

https://security.alpinelinux.org/vuln/CVE-2021-21231

https://security.alpinelinux.org/vuln/CVE-2021-21233

Plugin Details

Severity: Critical

ID: 406833

Version: Revision 1.37

Type: Local

Published: 10/31/2023

Updated: 2/27/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Critical

Score: 9.6

Percentile: 99.95

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-21233

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 9.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2021-21223

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 4/13/2021

CISA Known Exploited Vulnerability Due Dates: 11/17/2021

Exploitable With

Metasploit (Google Chrome versions before 89.0.4389.128 V8 XOR Typer Out-Of-Bounds Access RCE)

Reference Information

CVE: CVE-2021-21201, CVE-2021-21202, CVE-2021-21203, CVE-2021-21204, CVE-2021-21206, CVE-2021-21207, CVE-2021-21209, CVE-2021-21213, CVE-2021-21214, CVE-2021-21217, CVE-2021-21219, CVE-2021-21220, CVE-2021-21221, CVE-2021-21222, CVE-2021-21223, CVE-2021-21224, CVE-2021-21225, CVE-2021-21227, CVE-2021-21230, CVE-2021-21231, CVE-2021-21233