MGASA-2024-0017
Dashboard / Vulnerabilities / MGASA-2024-0017
MGASA-2024-0017
Summary: Updated chromium-browser-stable packages fix security vulnerabilities
Details: The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06. High CVE-2024-0518: Type Confusion in V8. Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03. High CVE-2024-0519: Out of bounds memory access in V8. Reported by Anonymous on 2024-01-11. Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.
References: https://advisories.mageia.org/MGASA-2024-0017.html, https://bugs.mageia.org/show_bug.cgi?id=32725, https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
Affected packages
Package
Name: chromium-browser-stable
Purl: pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-9
Affected ranges
Type: ECOSYSTEM
Events:
