Advisories ยป MGASA-2024-0017

Updated chromium-browser-stable packages fix security vulnerabilities

Publication date: 25 Jan 2024
Modification date: 25 Jan 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-0517 , CVE-2024-0518 , CVE-2024-0519

Description

The chromium-browser-stable package has been updated to the
120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are
listed below:
High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto)
Pham of Qrious Secure on 2024-01-06.
High CVE-2024-0518: Type Confusion in V8. Reported by Ganjiang
Zhou(@refrain_areu) of ChaMd5-H1 team on 2023-12-03.
High CVE-2024-0519: Out of bounds memory access in V8. Reported by
Anonymous on 2024-01-11.
Google is aware of reports that an exploit for CVE-2024-0519 exists in
the wild.
                

References

SRPMS

9/tainted