From d5614af0cb9922dfa5e27d9656c69b2163f9f6ed Mon Sep 17 00:00:00 2001 From: tigro Date: Thu, 29 Aug 2024 07:13:38 +0300 Subject: [PATCH] - update to 128.0.6613.113 * High CVE-2024-7969: Type Confusion in V8 * High CVE-2024-8193: Heap buffer overflow in Skia * High CVE-2024-8194: Type Confusion in V8 * High CVE-2024-8198: Heap buffer overflow in Skia --- .chromium.metadata | 2 +- .gitignore | 2 +- SPECS/chromium.spec | 9 ++++++++- 3 files changed, 10 insertions(+), 3 deletions(-) diff --git a/.chromium.metadata b/.chromium.metadata index 1317406f..5f4f7b8e 100644 --- a/.chromium.metadata +++ b/.chromium.metadata @@ -1,6 +1,6 @@ ccd15016324e640c40f6fc01ab076dc52196ea54 SOURCES/msspi-e91bd46306cc7044b2903cd07b788c13c36481e3.tar.xz 9bd36edf9f2e882aad828ad88faa7b9d02566cea SOURCES/Chromium-Gost-648cc5b901f2447b9b12bc5b09b962ec802b025a.tar.xz -26ec29f42493404445254ebc41972ba9e69b51fe SOURCES/chromium-128.0.6613.84.tar.xz +81fc28ecc7beed0dcfc5208c492865ed447c3389 SOURCES/chromium-128.0.6613.113.tar.xz dea187019741602d57aaf189a80abba261fbd2aa SOURCES/linux-x64-0.19.2.tgz 7e5d2c7864c5c83ec789b59c77cd9c20d2594916 SOURCES/linux-arm64-0.19.2.tgz 769196d081c6a0ad37f1c63dec56febfff3370de SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/.gitignore b/.gitignore index d9e3ce38..1fd8b0ad 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,4 @@ -SOURCES/chromium-128.0.6613.84.tar.xz +SOURCES/chromium-128.0.6613.113.tar.xz SOURCES/linux-x64-0.19.2.tgz SOURCES/linux-arm64-0.19.2.tgz SOURCES/node-v20.6.1-linux-x64.tar.xz diff --git a/SPECS/chromium.spec b/SPECS/chromium.spec index 2c13d125..be904f4d 100644 --- a/SPECS/chromium.spec +++ b/SPECS/chromium.spec @@ -337,7 +337,7 @@ %endif Name: chromium%{chromium_channel} -Version: 128.0.6613.84 +Version: 128.0.6613.113 Release: 1%{?dist}.inferit Summary: A WebKit (Blink) powered web browser that Google doesn't want you to use Url: http://www.chromium.org/Home @@ -2200,6 +2200,13 @@ getent group chrome-remote-desktop >/dev/null || groupadd -r chrome-remote-deskt %endif %changelog +* Thu Aug 29 2024 Arkady L. Shane - 128.0.6613.113-1.inferit +- update to 128.0.6613.113 + * High CVE-2024-7969: Type Confusion in V8 + * High CVE-2024-8193: Heap buffer overflow in Skia + * High CVE-2024-8194: Type Confusion in V8 + * High CVE-2024-8198: Heap buffer overflow in Skia + * Thu Aug 29 2024 Arkady L. Shane - 128.0.6613.84-1.inferit - update to 128.0.6613.84 * High CVE-2024-7964: Use after free in Passwords