MGASA-2024-0017 - Updated chromium-browser-stable packages fix security vulnerabilities

Publication date: 25 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0017.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-0517,
     CVE-2024-0518,
     CVE-2024-0519

The chromium-browser-stable package has been updated to the
120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are
listed below:
High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto)
Pham of Qrious Secure on 2024-01-06.
High CVE-2024-0518: Type Confusion in V8. Reported by Ganjiang
Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03.
High CVE-2024-0519: Out of bounds memory access in V8. Reported by
Anonymous on 2024-01-11.
Google is aware of reports that an exploit for CVE-2024-0519 exists in
the wild.

References:
- https://bugs.mageia.org/show_bug.cgi?id=32725
- https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0517
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0518
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0519

SRPMS:
- 9/tainted/chromium-browser-stable-120.0.6099.224-1.mga9.tainted

Mageia 2024-0017: chromium-browser-stable security update

The chromium-browser-stable package has been updated to the 120.0.6099.224 release

Summary

The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06. High CVE-2024-0518: Type Confusion in V8. Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03. High CVE-2024-0519: Out of bounds memory access in V8. Reported by Anonymous on 2024-01-11. Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild.

References

- https://bugs.mageia.org/show_bug.cgi?id=32725

- https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0517

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0518

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-0519

Resolution

MGASA-2024-0017 - Updated chromium-browser-stable packages fix security vulnerabilities

SRPMS

- 9/tainted/chromium-browser-stable-120.0.6099.224-1.mga9.tainted

Severity
Publication date: 25 Jan 2024
URL: https://advisories.mageia.org/MGASA-2024-0017.html
Type: security
CVE: CVE-2024-0517, CVE-2024-0518, CVE-2024-0519

Related News