{"id":"MGASA-2023-0322","summary":"Updated chromium-browser-stable packages fix bugs and vulnerabilities","details":"The chromium-browser-stable package has been updated to the\n119.0.6045.159 release, fixing bugs and 15 vulnerabilities, together\nwith 119.0.6045.123 and 119.0.6045.105; some of them are listed below:\n\nHigh CVE-2023-5480: Inappropriate implementation in Payments. Reported\nby Vsevolod Kokorin (Slonser) of Solidlab on 2023-10-14\n\nHigh CVE-2023-5482: Insufficient data validation in USB. Reported by\nDarkNavy on 2023-10-13\n\nHigh CVE-2023-5849: Integer overflow in USB. Reported by DarkNavy on\n2023-10-13\n\nHigh CVE-2023-5996: Use after free in WebAudio. Reported by Huang Xilin\nof Ant Group Light-Year Security Lab via Tianfu Cup 2023 on 2023-10-30\n\nHigh CVE-2023-5997: Use after free in Garbage Collection. Reported by\nAnonymous on 2023-10-31\n\nHigh CVE-2023-6112: Use after free in Navigation. Reported by Sergei\nGlazunov of Google Project Zero on 2023-11-04\n\nMedium CVE-2023-5850: Incorrect security UI in Downloads. Reported by\nMohit Raj (shadow2639)  on 2021-12-22\n\nMedium CVE-2023-5851: Inappropriate implementation in Downloads.\nReported by Shaheen Fazim on 2023-08-18\n\nMedium CVE-2023-5852: Use after free in Printing. Reported by [pwn2car]\non 2023-09-10\n\nMedium CVE-2023-5853: Incorrect security UI in Downloads. Reported by\nHafiizh on 2023-06-22\n\nMedium CVE-2023-5854: Use after free in Profiles. Reported by Dohyun Lee\n(@l33d0hyun) of SSD-Disclosure Labs & DNSLab, Korea Univ on 2023-10-01\n\nMedium CVE-2023-5855: Use after free in Reading Mode. Reported by\nChaobinZhang on 2023-10-13\n\nMedium CVE-2023-5856: Use after free in Side Panel. Reported by Weipeng\nJiang (@Krace) of VRI on 2023-10-17\n\nMedium CVE-2023-5857: Inappropriate implementation in Downloads.\nReported by Will Dormann on 2023-10-18\n\nLow CVE-2023-5858: Inappropriate implementation in WebApp Provider.\nReported by Axel Chong on 2023-06-24\n\nLow CVE-2023-5859: Incorrect security UI in Picture In Picture. Reported\nby Junsung Lee on 2023-09-13\n","modified":"2026-04-16T04:42:54.165228642Z","published":"2023-11-20T10:04:11Z","upstream":["CVE-2023-5480","CVE-2023-5482","CVE-2023-5849","CVE-2023-5850","CVE-2023-5851","CVE-2023-5852","CVE-2023-5853","CVE-2023-5854","CVE-2023-5855","CVE-2023-5856","CVE-2023-5857","CVE-2023-5858","CVE-2023-5859","CVE-2023-5996","CVE-2023-5997","CVE-2023-6112"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2023-0322.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=32529"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop_14.html"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2023/11/stable-channel-update-for-desktop.html"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2023/10/stable-channel-update-for-desktop_31.html"},{"type":"WEB","url":"https://www.gearrice.com/update/chrome-119-backs-up-and-finally-syncs-your-tabs/"}],"affected":[{"package":{"name":"chromium-browser-stable","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/chromium-browser-stable?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"119.0.6045.159-1.mga9.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2023-0322.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}