MGASA-2024-0017

Source
https://advisories.mageia.org/MGASA-2024-0017.html
Import Source
https://advisories.mageia.org/MGASA-2024-0017.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0017
Related
Published
2024-01-25T11:21:08Z
Modified
2024-01-25T11:09:22Z
Summary
Updated chromium-browser-stable packages fix security vulnerabilities
Details

The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06. High CVE-2024-0518: Type Confusion in V8. Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03. High CVE-2024-0519: Out of bounds memory access in V8. Reported by Anonymous on 2024-01-11. Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.

References
Credits

Affected packages

Mageia:9 / chromium-browser-stable

Package

Name
chromium-browser-stable
Purl
pkg:rpm/mageia/chromium-browser-stable?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
120.0.6099.224-1.mga9.tainted

Ecosystem specific

{
    "section": "tainted"
}