Bug 1219661

Summary: VUL-0: chromium,ungoogled-chromium: multiple vulnerabilities fixed in 121.0.6167.160
Product: [openSUSE] openSUSE Tumbleweed Reporter: Thomas Leroy <thomas.leroy>
Component: SecurityAssignee: Andreas Stieger <Andreas.Stieger>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: gmbr3, m.szczepaniak.000
Version: Current   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Thomas Leroy 2024-02-07 08:43:29 UTC
The Stable channel has been updated to 121.0.6167.160 for Mac and Linux and 121.0.6167.160/161 to Windows which will roll out over the coming days/weeks. A full list of changes in this build is available in the log.

Security Fixes and Rewards

This update includes 3 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information.

- High CVE-2024-1284: Use after free in Mojo. Reported by Anonymous on 2024-01-25
- High CVE-2024-1283: Heap buffer overflow in Skia. Reported by Jorge Buzeti (@r3tr074) on 2024-01-25

References:
https://chromereleases.googleblog.com/2024/02/stable-channel-update-for-desktop.html
Comment 1 OBSbugzilla Bot 2024-03-06 15:35:07 UTC
This is an autogenerated message for OBS integration:
This bug (1219661) was mentioned in
https://build.opensuse.org/request/show/1155575 Factory / chromium
Comment 2 OBSbugzilla Bot 2024-03-10 21:35:06 UTC
This is an autogenerated message for OBS integration:
This bug (1219661) was mentioned in
https://build.opensuse.org/request/show/1156764 Factory / ungoogled-chromium
Comment 3 OBSbugzilla Bot 2024-03-12 11:35:04 UTC
This is an autogenerated message for OBS integration:
This bug (1219661) was mentioned in
https://build.opensuse.org/request/show/1157120 Backports:SLE-15-SP5 / chromium
Comment 4 OBSbugzilla Bot 2024-03-13 13:35:03 UTC
This is an autogenerated message for OBS integration:
This bug (1219661) was mentioned in
https://build.opensuse.org/request/show/1157505 Backports:SLE-15-SP5 / chromium
Comment 5 Marcus Meissner 2024-03-18 10:56:53 UTC
released