Security Update Chromium Component (MINDBREEZE27447)

ID: MINDBREEZE27447 
Affected Components: Mindbreeze InSpire G7, Mindbreeze InSpire SaaS 
Severity: 8.8 High 
Status: Final 
First published: October 20, 2023 
CVEs: CVE-2023-2721, CVE-2023-2723, CVE-2023-2724, CVE-2023-2929, CVE-2023-2931, CVE-2023-2932, CVE-2023-2933, CVE-2023-2934, CVE-2023-2935, CVE-2023-2936, CVE-2023-3216, CVE-2023-3079, CVE-2023-3420, CVE-2023-3421 

Summary

Security Update Chromium Component

  • CVE-2023-2721 chromium - Component: Navigation - Unknown code block - Use after free
  • CVE-2023-2723 chromium - Component: DevTools - Unknown processing - Use after free
  • CVE-2023-2724 chromium - Type confusion in V8 - Use after free
  • CVE-2023-2929 chromium - Component: Out of bounds write in Swiftshader
  • CVE-2023-2931 chromium - Component: Use after free in PDF
  • CVE-2023-2932 chromium - Component: Use after free in PDF
  • CVE-2023-2933 chromium - Component: Use after free in PDF
  • CVE-2023-2934 chromium - Component: Out of bounds memory access in Mojo
  • CVE-2023-2935 chromium - Component: Type Confusion in V8
  • CVE-2023-2936 chromium - Component: Type Confusion in V8
  • CVE-2023-3216 chromium - Component: Type confusion in V8
  • CVE-2023-3079 chromium - Component: Type confusion in V8
  • CVE-2023-3420 chromium - Component: Type confusion in V8
  • CVE-2023-3421 chromium - Compinent: Use after free in Media

 

Hotfix Information

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 23.4 Release 

  • Mindbreeze InSpire SaaS 23.4 Release