Security Update Chromium Component (MINDBREEZE27958)

ID: MINDBREEZE27958 
Affected Components: Mindbreeze InSpire G7, Mindbreeze InSpire SaaS 
Severity: 8.8 High 
Status: Final 
First published: September 29, 2023 
CVEs: CVE-2023-4068, CVE-2023-4069, CVE-2023-4070, CVE-2023-4071, CVE-2023-4072, CVE-2023-4073, CVE-2023-4074, CVE-2023-3732, CVE-2023-3216, CVE-2023-3079, CVE-2023-3420, CVE-2023-3421 

Summary

Security Update Chromium Component

  • CVE-2023-4068 chromium - Component: Type Confusion in V8.
  • CVE-2023-4069 chromium - Component: Type Confusion in V8.
  • CVE-2023-4070 chromium - Component: Type Confusion in V8.
  • CVE-2023-4071 chromium - Component: Heap buffer overflow in Visuals.
  • CVE-2023-4072 chromium - Component: Out of bounds read and write in WebGL.
  • CVE-2023-4073 chromium - Component: Out of bounds memory access in ANGLE.
  • CVE-2023-4074 chromium - Component: Use after free in Blink Task Scheduling.
  • CVE-2023-3732 chromium - Component: Out of bounds memory access in Mojo.
  • ​​​​​​CVE-2023-3216 chromium - Component: Type confusion in V8
  • CVE-2023-3079 chromium - Component: Type confusion in V8
  • CVE-2023-3420 chromium - Component: Type confusion in V8
  • CVE-2023-3421 chromium - Compinent: Use after free in Media

 

Hotfix Information

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 23.5 Release 

  • Mindbreeze InSpire SaaS 23.5 Release