Alerts This Week
Warning Icon 1 409
Alerts This Week
Warning Icon 1 409

Gentoo 202401-34 High: Remote Code Execution in Chromium and Edge

gentoo
Calendar Grey January 31, 2024
Dist Gentoo Esm H88
The FreeBSD Security Advisory FreeBSD-SA-2024-02 highlights critical vulnerabilities identified in FreeBSD's kernel and userland components.
Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution.

Summary

Multiple vulnerabilities have been discovered in Chromium and its derivatives. Please review the CVE identifiers referenced below for details.

Resolution

All Google Chrome users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/google-chrome-120.0.6099.109"
All Chromium users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/chromium-120.0.6099.109"
All Microsoft Edge users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-120.0.2210.133"

References

[ 1 ] CVE-2023-2312 https://nvd.nist.gov/vuln/detail/CVE-2023-2312 [ 2 ] CVE-2023-2929 https://nvd.nist.gov/vuln/detail/CVE-2023-2929 [ 3 ] CVE-2023-2930 https://nvd.nist.gov/vuln/detail/CVE-2023-2930 [ 4 ] CVE-2023-2931 https://nvd.nist.gov/vuln/detail/CVE-2023-2931 [ 5 ] CVE-2023-2932 https://nvd.nist.gov/vuln/detail/CVE-2023-2932 [ 6 ] CVE-2023-2933 https://nvd.nist.gov/vuln/detail/CVE-2023-2933 [ 7 ] CVE-2023-2934 https://nvd.nist.gov/vuln/detail/CVE-2023-2934 [ 8 ] CVE-2023-2935 https://nvd.nist.gov/vuln/detail/CVE-2023-2935 [ 9 ] CVE-2023-2936 https://nvd.nist.gov/vuln/detail/CVE-2023-2936 [ 10 ] CVE-2023-2937 https://nvd.nist.gov/vuln/detail/CVE-2023-2937 [ 11 ] CVE-2023-2938 https://nvd.nist.gov/vuln/detail/CVE-2023-2938 [ 12 ] CVE-2023-2939 https://nvd.nist.gov/vuln/detail/CVE-2023-2939 [ 13 ] CVE-2023-2940 https://nvd.nist.gov/vuln/detail/CVE-2023-2940 [ 14 ] CVE-2023-2941 https://nvd.nist....

Read the Full Advisory

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
https://security.gentoo.org/glsa/202401-34
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity: High
Title: Chromium, Google Chrome, Microsoft Edge: Multiple Vulnerabilities
Date: January 31, 2024
Bugs: #907999, #908471, #909283, #910522, #911675, #912364, #913016, #913710, #914350, #914871, #915137, #915560, #915961, #916252, #916620, #917021, #917357, #918882, #919321, #919802, #920442, #921337
ID: 202401-34

Synopsis

Multiple vulnerabilities have been discovered in Chromium and its derivatives, the worst of which can lead to remote code execution.

Background

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.
Google Chrome is one fast, simple, and secure browser for all your devices.
Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Package Vulnerable Unaffected ------------------------- ---------------- ----------------- www-client/chromium < 120.0.6099.109 >= 120.0.6099.109 www-client/google-chrome < 120.0.6099.109 >= 120.0.6099.109 www-client/microsoft-edge < 120.0.2210.133 >= 120.0.2210.133

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time.

Your message here