Fedora EPEL 7 updates-testing report
by updates@fedoraproject.org
The following Fedora EPEL 7 Security updates need testing:
Age URL
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-3f86ec863a seamonkey-2.53.18.2-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
chromium-123.0.6312.58-1.el7
Details about builds:
================================================================================
chromium-123.0.6312.58-1.el7 (FEDORA-EPEL-2024-15cde9f00b)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 123.0.6312.58
* High CVE-2024-2625: Object lifecycle issue in V8
* Medium CVE-2024-2626: Out of bounds read in Swiftshader
* Medium CVE-2024-2627: Use after free in Canvas
* Medium CVE-2024-2628: Inappropriate implementation in Downloads
* Medium CVE-2024-2629: Incorrect security UI in iOS
* Medium CVE-2024-2630: Inappropriate implementation in iOS
* Low CVE-2024-2631: Inappropriate implementation in iOS
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 20 2024 Than Ngo <than(a)redhat.com> - 123.0.6312.58-1
- update to 123.0.6312.58
* High CVE-2024-2625: Object lifecycle issue in V8
* Medium CVE-2024-2626: Out of bounds read in Swiftshader
* Medium CVE-2024-2627: Use after free in Canvas
* Medium CVE-2024-2628: Inappropriate implementation in Downloads
* Medium CVE-2024-2629: Incorrect security UI in iOS
* Medium CVE-2024-2630: Inappropriate implementation in iOS
* Low CVE-2024-2631: Inappropriate implementation in iOS
* Fri Mar 15 2024 Than Ngo <than(a)redhat.com> - 123.0.6312.46-1
- update to 123.0.6312.46
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2269307 - CVE-2024-2400 chromium: chromium-browser: Use after free in Performance Manager [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2269307
[ 2 ] Bug #2270390 - CVE-2024-2626 CVE-2024-2627 CVE-2024-2628 CVE-2024-2629 CVE-2024-2630 CVE-2024-2631 chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2270390
[ 3 ] Bug #2270392 - CVE-2024-2625 chromium: chromium-browser: Object lifecycle issue in V8 [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2270392
--------------------------------------------------------------------------------