Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 9 MGASA-2024-0314 Critical gnome-shell JavaScript Threat

mageia
Calendar Grey September 27, 2024
Dist Mageia Esm H88
Revised gnome-shell updates for Mageia address security vulnerabilities and resource concerns. Release date: 27 Sep 2024.
In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who c...

Summary

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior. (CVE-2024-36472)

References

- https://bugs.mageia.org/show_bug.cgi?id=33434

- https://lists.suse.com/pipermail/sle-updates/2024-July/036098.html

- https://ubuntu.com/security/notices/USN-6963-1

- https://www.cve.org/CVERecord?id=CVE-2024-36472

Resolution

SRPMS

- 9/core/gnome-shell-44.2-1.2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 Sep 2024
URL: https://advisories.mageia.org/MGASA-2024-0314.html
Type: security
CVE: CVE-2024-36472

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here