Alpine: multiple qt5-qtwebengine packages: security update to 5.15.3_git20220505-r4

critical Tenable Self-Hosted Container Security Plugin ID 406858

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Heap buffer overflow in WebSQL in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
(CVE-2022-3446)

- Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (CVE-2022-3038)

- Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2022-3040)

- Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2022-3041)

- Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker
who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2022-3075)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-3038

https://security.alpinelinux.org/vuln/CVE-2022-3040

https://security.alpinelinux.org/vuln/CVE-2022-3041

https://security.alpinelinux.org/vuln/CVE-2022-3075

https://security.alpinelinux.org/vuln/CVE-2022-3196

https://security.alpinelinux.org/vuln/CVE-2022-3197

https://security.alpinelinux.org/vuln/CVE-2022-3198

https://security.alpinelinux.org/vuln/CVE-2022-3199

https://security.alpinelinux.org/vuln/CVE-2022-3201

https://security.alpinelinux.org/vuln/CVE-2022-3304

https://security.alpinelinux.org/vuln/CVE-2022-3370

https://security.alpinelinux.org/vuln/CVE-2022-3446

https://security.alpinelinux.org/vuln/CVE-2022-35737

Plugin Details

Severity: Critical

ID: 406858

Version: Revision 1.28

Type: Local

Published: 10/31/2023

Updated: 6/1/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.1

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-3446

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2022-3075

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 8/3/2022

CISA Known Exploited Vulnerability Due Dates: 9/29/2022, 4/20/2023

Reference Information

CVE: CVE-2022-3038, CVE-2022-3040, CVE-2022-3041, CVE-2022-3075, CVE-2022-3196, CVE-2022-3197, CVE-2022-3198, CVE-2022-3199, CVE-2022-3201, CVE-2022-3304, CVE-2022-3370, CVE-2022-3446, CVE-2022-35737