===========================================================================
             AUSCERT External Security Bulletin Redistribution             
                                                                           
                               ESB-2024.2450                               
                         chromium security update                          
                               22 April 2024                               
                                                                           
===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           chromium                                                
Publisher:         Debian                                                  
Operating System:  Debian GNU/Linux                                        
Resolution:        Patch/Upgrade                                           
CVE Names:         CVE-2024-3832 CVE-2024-3833 CVE-2024-3834               
                   CVE-2024-3837 CVE-2024-3838 CVE-2024-3839               
                   CVE-2024-3840 CVE-2024-3841 CVE-2024-3843               
                   CVE-2024-3844 CVE-2024-3845 CVE-2024-3846               
                   CVE-2024-3847                                           

Original Bulletin:
   https://lists.debian.org/debian-security-announce/2024/msg00077.html

Comment: CVSS (Max):  8.8* CVE-2024-3837 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
         CVSS Source: NIST                                                 
         Calculator:  https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
         * Not all CVSS available when published                           


- --------------------------BEGIN INCLUDED TEXT--------------------

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5668-1                   security@debian.org
https://www.debian.org/security/                           Andres Salomon
April 20, 2024                        https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : chromium
CVE ID         : CVE-2024-3832 CVE-2024-3833 CVE-2024-3834 CVE-2024-3837
                 CVE-2024-3838 CVE-2024-3839 CVE-2024-3840 CVE-2024-3841
                 CVE-2024-3843 CVE-2024-3844 CVE-2024-3845 CVE-2024-3846
                 CVE-2024-3847

Security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.

For the stable distribution (bookworm), these problems have been fixed in
version 124.0.6367.60-1~deb12u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmYj8BEACgkQZF0CR8Nu
djfcpBAAiHu3u6NPHxwern9CkZS2BDCrsTy1ux2+UWe8ucWs6+ilN+DVdTH+r56p
VkVPlp2Kup76Zfx1rnL6/qb2J4o6Tbyq8DVu+prHHvVbfkwqr0Q0i7WF7DYa4Jr5
XRZLgVvuhO0MqGIgnNJJO6og5gnIMgM6XNUIEJh+JPaB0+akLFAsK7pW+e2YZ2E5
HqGdTJ8oHZN6Toca0gVZrW4xhzi0JdSyhqeNWkozK4JyTFkqWX5okYkpL7NwOrHB
R9xiF4rdWEHqHUQp+DaOC34cC4xfz4zX05Txbt1/7yb61Il9uCzQ99YnnYSJJieN
Yowj4rN8DzFMHVDKHeVbCy/82c5ctp2uue8BRh5PeJWqLiVzpGMe5XyBCn8hJS66
DJ6q3srfuhjgTkmuFzaBsnP9j2YZYV1fQlzjhadmL1YqWG8M2Fhi0vH0IYjK4d09
zFnLbT7S9UgHfUMAobWzIj534OMOS2MKrDn2xBZ1/fBdcBB/AV0fgdNjqEbKNV55
oCapZ8+uOy/cdQ+dGGjlZu7SKg9Q/Fvg/zQoPTgafQQb3nQV4ZfLybm37Czql8hf
ZtR0qyJZY/A7ThFb+cA6vaCoUAQ5Sie+JsiSDwklrRQ9EWrDF8mVo+N2safzf3hA
ciTWUxsRjxBsi1WyFPvVUJElXP4tVmHVi3+zX0TAsPnR0JfSd+M=
=3lPn
-----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT----------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================