Vulnerability CVE-2024-2627: Information

Description

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: March 20, 2024
Modified: April 1, 2024
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus123.0.6312.58-alt1124.0.6367.78-alt1ALT-PU-2024-4439-2343478Fixed
chromiumsisyphus_loongarch64123.0.6312.86-alt1.0.port123.0.6312.86-alt1.0.portALT-PU-2024-4809-1-Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      123.0.6312.58

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*