SUSE-SU-2024:4411-1
Not scored
Security update for mozjs115
This update for mozjs115 fixes the following issues: - CVE-2024-11498: Fixed resource exhaustion via Stack overflow in libjxl (bsc#1233786) - CVE-2024-11403: Fixed out of Bounds Memory Read/Write in libjxl (bsc#1233766) - CVE-2024-50602: Fixed DoS via XML_ResumeParser in libexpat (bsc#1232602)
Exploit probability
Not scored
Published
December 23, 2024
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2024:4411-1
View original source
This update for mozjs115 fixes the following issues: - CVE-2024-11498: Fixed resource exhaustion via Stack overflow in libjxl (bsc#1233786) - CVE-2024-11403: Fixed out of Bounds Memory Read/Write in libjxl (bsc#1233766) - CVE-2024-50602: Fixed DoS via XML_ResumeParser in libexpat (bsc#1232602)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1232599
- https://bugzilla.suse.com/1232602
- https://bugzilla.suse.com/1233766
- https://bugzilla.suse.com/1233786
- https://www.suse.com/security/cve/CVE-2024-11403
- https://www.suse.com/security/cve/CVE-2024-11498
- https://www.suse.com/security/cve/CVE-2024-50602
- https://www.suse.com/support/update/announcement/2024/suse-su-20244411-1/