DEBIAN-CVE-2024-4558

Source
https://security-tracker.debian.org/tracker/CVE-2024-4558
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-4558
Upstream
Downstream
Published
2024-05-07T19:15:08Z
Modified
2026-09-15T09:03:19Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

References

Affected packages

Debian:12
chromium

Package

Name
chromium
Purl
pkg:deb/debian/chromium?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
124.0.6367.155-1~deb12u1

Affected versions

113.*
113.0.5672.126-1
114.*
114.0.5735.90-1
114.0.5735.90-2~deb11u1
114.0.5735.90-2~deb12u1
114.0.5735.90-2
114.0.5735.106-1~deb11u1
114.0.5735.106-1~deb12u1
114.0.5735.106-1
114.0.5735.133-1~deb11u1
114.0.5735.133-1~deb12u1
114.0.5735.133-1
114.0.5735.198-1~deb11u1
114.0.5735.198-1~deb12u1
114.0.5735.198-1
115.*
115.0.5790.98-1~deb11u1
115.0.5790.98-1~deb12u1
115.0.5790.98-1
115.0.5790.98-2
115.0.5790.102-1
115.0.5790.102-2
115.0.5790.170-1~deb11u1
115.0.5790.170-1~deb12u1
115.0.5790.170-1
116.*
116.0.5845.96-1~deb11u1
116.0.5845.96-1~deb12u1
116.0.5845.96-1
116.0.5845.96-2
116.0.5845.110-1~deb11u1
116.0.5845.110-1~deb12u1
116.0.5845.110-1
116.0.5845.110-2
116.0.5845.140-1~deb11u1
116.0.5845.140-1~deb12u1
116.0.5845.140-1
116.0.5845.180-1~deb11u1
116.0.5845.180-1~deb12u1
116.0.5845.180-1
117.*
117.0.5938.62-1~deb11u1
117.0.5938.62-1~deb12u1
117.0.5938.62-1
117.0.5938.92-1
117.0.5938.132-1~deb11u1
117.0.5938.132-1~deb12u1
117.0.5938.132-1
117.0.5938.132-2
117.0.5938.149-1~deb11u1
117.0.5938.149-1~deb12u1
117.0.5938.149-1
118.*
118.0.5993.70-1~deb11u1
118.0.5993.70-1~deb12u1
118.0.5993.70-1
118.0.5993.117-1~deb11u1
118.0.5993.117-1~deb12u1
118.0.5993.117-1
119.*
119.0.6045.105-1~deb11u1
119.0.6045.105-1~deb12u1
119.0.6045.105-1
119.0.6045.123-1~deb11u1
119.0.6045.123-1~deb12u1
119.0.6045.123-1
119.0.6045.159-1~deb11u1
119.0.6045.159-1~deb12u1
119.0.6045.159-1
119.0.6045.199-1~deb11u1
119.0.6045.199-1~deb12u1
119.0.6045.199-1
120.*
120.0.6099.71-1~deb11u1
120.0.6099.71-1~deb12u1
120.0.6099.71-1
120.0.6099.109-1~deb11u1
120.0.6099.109-1~deb12u1
120.0.6099.109-1
120.0.6099.129-1~deb11u1
120.0.6099.129-1~deb12u1
120.0.6099.129-1
120.0.6099.199-1~deb11u1
120.0.6099.199-1~deb12u1
120.0.6099.199-1
120.0.6099.216-1~deb11u1
120.0.6099.216-1~deb12u1
120.0.6099.216-1
120.0.6099.224-1~deb11u1
120.0.6099.224-1~deb12u1
120.0.6099.224-1
120.0.6099.224-2
121.*
121.0.6167.85-1~deb12u1
121.0.6167.85-1
121.0.6167.139-1~deb12u1
121.0.6167.139-1
121.0.6167.160-1~deb12u1
121.0.6167.160-1
122.*
122.0.6261.57-1~deb12u1
122.0.6261.57-1
122.0.6261.94-1~deb12u1
122.0.6261.94-1
122.0.6261.111-1~deb12u1
122.0.6261.111-1
122.0.6261.128-1~deb12u1
122.0.6261.128-1
123.*
123.0.6312.58-1
123.0.6312.86-1~deb12u1
123.0.6312.86-1
123.0.6312.105-1~deb12u1
123.0.6312.105-1~deb13u1
123.0.6312.105-1
123.0.6312.105-2
123.0.6312.122-1~deb12u1
123.0.6312.122-1
124.*
124.0.6367.60-1~deb12u1
124.0.6367.60-1
124.0.6367.60-2
124.0.6367.78-1~deb12u1
124.0.6367.78-1
124.0.6367.118-1~deb12u1
124.0.6367.118-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.44.3-1~deb12u1

Affected versions

2.*
2.40.1-1
2.40.2-1~deb11u1
2.40.2-1~deb12u1
2.40.2-1
2.40.3-1
2.40.3-2~deb11u1
2.40.3-2~deb11u2
2.40.3-2~deb12u1
2.40.3-2~deb12u2
2.40.3-2
2.40.4-1
2.40.5-1~deb11u1
2.40.5-1~deb12u1
2.40.5-1
2.41.4-1
2.41.5-1
2.41.6-1
2.41.90-1
2.41.91-1
2.41.91-2
2.41.92-1
2.42.0-1~bpo12+1
2.42.0-1
2.42.1-1~bpo12+1
2.42.1-1~deb11u1
2.42.1-1~deb11u2
2.42.1-1~deb12u1
2.42.1-1
2.42.1-2
2.42.2-1~deb11u1
2.42.2-1~deb12u1
2.42.2-1
2.42.3-1~deb11u1
2.42.3-1~deb12u1
2.42.3-1
2.42.4-1~deb11u1
2.42.4-1~deb12u1
2.42.4-1
2.42.5-1~deb11u1
2.42.5-1~deb12u1
2.42.5-1
2.42.5-2
2.43.1-1
2.43.2-1
2.43.3-1
2.43.4-1
2.43.4-2
2.44.0-1
2.44.0-2
2.44.1-1~deb11u1
2.44.1-1~deb12u1
2.44.1-1
2.44.2-1~deb11u1
2.44.2-1~deb12u1
2.44.2-1
2.44.3-1~deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.38.6-1
2.39.91-1
2.40.0-1
2.40.1-1
2.40.2-1
2.40.2-2
2.40.3-1
2.40.4-1
2.40.5-1
2.42.0-1
2.42.1-1
2.42.2-1
2.42.3-1
2.42.4-1
2.42.5-1
2.42.5-1.1~exp1
2.42.5-1.1
2.42.5-1.2
2.42.5-2~exp
2.44.1-1
2.44.2-1
2.44.2-2
2.44.3-1
2.44.4-1
2.46.1-1
2.46.2-1
2.46.3-1
2.46.4-1
2.46.5-1
2.46.6-1
2.48.0-1
2.48.1-1
2.48.1-2
2.48.2-1
2.48.3-1
2.48.5-1
2.48.6-1
2.48.6-2
2.50.0-1
2.50.0-2
2.50.1-1
2.50.2-1
2.50.3-1
2.50.4-1
2.50.5-1
2.50.6-1
2.52.0-1
2.52.1-1
2.52.2-1
2.52.2-2
2.52.3-1
2.52.4-1
2.52.5-1
2.52.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
Debian:13
chromium

Package

Name
chromium
Purl
pkg:deb/debian/chromium?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
124.0.6367.155-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.44.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.44.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
Debian:14
chromium

Package

Name
chromium
Purl
pkg:deb/debian/chromium?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
124.0.6367.155-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
webkit2gtk

Package

Name
webkit2gtk
Purl
pkg:deb/debian/webkit2gtk?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.44.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"
wpewebkit

Package

Name
wpewebkit
Purl
pkg:deb/debian/wpewebkit?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.44.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-4558.json"