{"id":"MGASA-2024-0314","summary":"Updated gnome-shell packages fix security vulnerability","details":"In GNOME Shell through 45.7, a portal helper can be launched\nautomatically (without user confirmation) based on network responses\nprovided by an adversary (e.g., an adversary who controls the local\nWi-Fi network), and subsequently loads untrusted JavaScript code, which\nmay lead to resource consumption or other impacts depending on the\nJavaScript code's behavior. (CVE-2024-36472)\n","modified":"2026-04-16T04:40:53.769664824Z","published":"2024-09-27T01:30:52Z","upstream":["CVE-2024-36472"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0314.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33434"},{"type":"WEB","url":"https://lists.suse.com/pipermail/sle-updates/2024-July/036098.html"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6963-1"}],"affected":[{"package":{"name":"gnome-shell","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/gnome-shell?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"44.2-1.2.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0314.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}