Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2055-1

Опубликовано: 25 июл. 2018
Источник: suse-cvrf

Описание

Security update for Chromium

This update for Chromium to version 67.0.3396.99 fixes multiple issues.

Security issues fixed (bsc#1095163):

  • CVE-2018-6123: Use after free in Blink
  • CVE-2018-6124: Type confusion in Blink
  • CVE-2018-6125: Overly permissive policy in WebUSB
  • CVE-2018-6126: Heap buffer overflow in Skia
  • CVE-2018-6127: Use after free in indexedDB
  • CVE-2018-6129: Out of bounds memory access in WebRTC
  • CVE-2018-6130: Out of bounds memory access in WebRTC
  • CVE-2018-6131: Incorrect mutability protection in WebAssembly
  • CVE-2018-6132: Use of uninitialized memory in WebRTC
  • CVE-2018-6133: URL spoof in Omnibox
  • CVE-2018-6134: Referrer Policy bypass in Blink
  • CVE-2018-6135: UI spoofing in Blink
  • CVE-2018-6136: Out of bounds memory access in V8
  • CVE-2018-6137: Leak of visited status of page in Blink
  • CVE-2018-6138: Overly permissive policy in Extensions
  • CVE-2018-6139: Restrictions bypass in the debugger extension API
  • CVE-2018-6140: Restrictions bypass in the debugger extension API
  • CVE-2018-6141: Heap buffer overflow in Skia
  • CVE-2018-6142: Out of bounds memory access in V8
  • CVE-2018-6143: Out of bounds memory access in V8
  • CVE-2018-6144: Out of bounds memory access in PDFium
  • CVE-2018-6145: Incorrect escaping of MathML in Blink
  • CVE-2018-6147: Password fields not taking advantage of OS protections in Views
  • CVE-2018-6148: Incorrect handling of CSP header (boo#1096508)
  • CVE-2018-6149: Out of bounds write in V8 (boo#1097452)

The following tracked packaging changes are included:

  • Require ffmpeg >= 4.0 (boo#1095545)

Список пакетов

SUSE Package Hub for SUSE Linux Enterprise 12 SP2
chromedriver-67.0.3396.99-58.2
chromium-67.0.3396.99-58.2

Описание

A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromedriver-67.0.3396.99-58.2
SUSE Package Hub for SUSE Linux Enterprise 12 SP2:chromium-67.0.3396.99-58.2

Ссылки
Уязвимость openSUSE-SU-2018:2055-1