Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2016:0491-1

Опубликовано: 17 фев. 2016
Источник: suse-cvrf

Описание

Security update for Chromium

This update to Chromium 48.0.2564.109 fixes the following issues:

Security fixes (boo#965999):

  • CVE-2016-1622: Same-origin bypass in Extensions
  • CVE-2016-1623: Same-origin bypass in DOM
  • CVE-2016-1624: Buffer overflow in Brotli
  • CVE-2016-1625: Navigation bypass in Chrome Instant
  • CVE-2016-1626: Out-of-bounds read in PDFium
  • CVE-2016-1627: Various fixes from internal audits, fuzzing and other initiatives

Non-security bug fixes:

  • boo#965738: resolve issues with specific banking websites when built against system libraries
  • boo#966082: chromium: sandbox related stacktrace printed
  • boo#965566: Drop libva support
  • Prevent graphical issues related to libjpeg
  • On KDE 5 kwallet5 is the default password store now

Список пакетов

openSUSE Leap 42.1
chromedriver-48.0.2564.109-21.1
chromium-48.0.2564.109-21.1
chromium-desktop-gnome-48.0.2564.109-21.1
chromium-desktop-kde-48.0.2564.109-21.1
chromium-ffmpegsumo-48.0.2564.109-21.1

Описание

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки

Описание

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, related to FrameLoader.cpp, HTMLFrameOwnerElement.h, LocalFrame.cpp, and WebLocalFrameImpl.cpp.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки

Описание

Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted data with brotli compression.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки

Описание

The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors, related to instant_service.cc and search_tab_helper.cc.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки

Описание

The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки

Описание

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to bypass intended access restrictions via a crafted URL, related to browser/devtools/devtools_ui_bindings.cc and WebKit/Source/devtools/front_end/Runtime.js.


Затронутые продукты
openSUSE Leap 42.1:chromedriver-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-gnome-48.0.2564.109-21.1
openSUSE Leap 42.1:chromium-desktop-kde-48.0.2564.109-21.1

Ссылки