MGASA-2023-0322

Source
https://advisories.mageia.org/MGASA-2023-0322.html
Import Source
https://advisories.mageia.org/MGASA-2023-0322.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2023-0322
Related
Published
2023-11-20T10:04:11Z
Modified
2023-11-20T08:39:17Z
Summary
Updated chromium-browser-stable packages fix bugs and vulnerabilities
Details

The chromium-browser-stable package has been updated to the 119.0.6045.159 release, fixing bugs and 15 vulnerabilities, together with 119.0.6045.123 and 119.0.6045.105; some of them are listed below:

High CVE-2023-5480: Inappropriate implementation in Payments. Reported by Vsevolod Kokorin (Slonser) of Solidlab on 2023-10-14

High CVE-2023-5482: Insufficient data validation in USB. Reported by DarkNavy on 2023-10-13

High CVE-2023-5849: Integer overflow in USB. Reported by DarkNavy on 2023-10-13

High CVE-2023-5996: Use after free in WebAudio. Reported by Huang Xilin of Ant Group Light-Year Security Lab via Tianfu Cup 2023 on 2023-10-30

High CVE-2023-5997: Use after free in Garbage Collection. Reported by Anonymous on 2023-10-31

High CVE-2023-6112: Use after free in Navigation. Reported by Sergei Glazunov of Google Project Zero on 2023-11-04

Medium CVE-2023-5850: Incorrect security UI in Downloads. Reported by Mohit Raj (shadow2639) on 2021-12-22

Medium CVE-2023-5851: Inappropriate implementation in Downloads. Reported by Shaheen Fazim on 2023-08-18

Medium CVE-2023-5852: Use after free in Printing. Reported by [pwn2car] on 2023-09-10

Medium CVE-2023-5853: Incorrect security UI in Downloads. Reported by Hafiizh on 2023-06-22

Medium CVE-2023-5854: Use after free in Profiles. Reported by Dohyun Lee (@l33d0hyun) of SSD-Disclosure Labs & DNSLab, Korea Univ on 2023-10-01

Medium CVE-2023-5855: Use after free in Reading Mode. Reported by ChaobinZhang on 2023-10-13

Medium CVE-2023-5856: Use after free in Side Panel. Reported by Weipeng Jiang (@Krace) of VRI on 2023-10-17

Medium CVE-2023-5857: Inappropriate implementation in Downloads. Reported by Will Dormann on 2023-10-18

Low CVE-2023-5858: Inappropriate implementation in WebApp Provider. Reported by Axel Chong on 2023-06-24

Low CVE-2023-5859: Incorrect security UI in Picture In Picture. Reported by Junsung Lee on 2023-09-13

References
Credits

Affected packages