Security Update Chromium Component (MINDBREEZE29950)

ID: MINDBREEZE29950 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 8.8 High 
Status: Final 
First published: March 18, 2024 
CVEs: CVE-2023-7024 CVE-2024-0222 CVE-2024-0223 CVE-2024-0224 CVE-2023-7024 CVE-2024-0807 CVE-2024-0812 CVE-2024-0808 CVE-2024-0810 CVE-2024-0517 CVE-2024-0518 CVE-2024-0519 

Summary

Security Update Chromium Component

  • CVE-2023-7024 chromium - Component: Heap buffer overflow in WebRTC.
  • CVE-2024-0222 chromium - Component: Use after free in ANGLE.
  • CVE-2024-0223 chromium - Component: Heap buffer overflow in ANGLE.
  • CVE-2024-0224 chromium - Component: Use after free in WebAudio.
  • CVE-2023-7024 chromium - Component: Heap buffer overflow in WebRTC.
  • CVE-2024-0807 chromium - Component: Use after free in WebAudio.
  • CVE-2024-0812 chromium - Component: Inappropriate implementation in Accessibility.
  • CVE-2024-0808 chromium - Component: Integer underflow in WebUI.
  • CVE-2024-0810 chromium - Component: Insufficient policy enforcement in DevTools.
  • CVE-2024-0517 chromium - Component: Out of bounds write in V8.
  • CVE-2024-0518 chromium - Component: Type Confusion in V8.
  • CVE-2024-0519 chromium - Component: Out of bounds memory access in V8.

 

Hotfix Information

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 24.1 Release 
  • Mindbreeze InSpire SaaS 24.1 Release