Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1557-1

Опубликовано: 15 июн. 2019
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium to version 75.0.3770.80 fixes the following issues:

Security issues fixed:

  • CVE-2019-5828: Fixed a Use after free in ServiceWorker
  • CVE-2019-5829: Fixed Use after free in Download Manager
  • CVE-2019-5830: Fixed an incorrectly credentialed requests in CORS
  • CVE-2019-5831: Fixed an incorrect map processing in V8
  • CVE-2019-5832: Fixed an incorrect CORS handling in XHR
  • CVE-2019-5833: Fixed an inconsistent security UI placemen
  • CVE-2019-5835: Fixed an out of bounds read in Swiftshader
  • CVE-2019-5836: Fixed a heap buffer overflow in Angle
  • CVE-2019-5837: Fixed a cross-origin resources size disclosure in Appcache
  • CVE-2019-5838: Fixed an overly permissive tab access in Extensions
  • CVE-2019-5839: Fixed an incorrect handling of certain code points in Blink
  • CVE-2019-5840: Fixed a popup blocker bypass
  • CVE-2019-5834: Fixed a URL spoof in Omnibox on iOS

Список пакетов

openSUSE Leap 15.1
chromedriver-75.0.3770.80-lp151.2.6.1
chromium-75.0.3770.80-lp151.2.6.1

Описание

Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки

Описание

Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-75.0.3770.80-lp151.2.6.1
openSUSE Leap 15.1:chromium-75.0.3770.80-lp151.2.6.1

Ссылки
Уязвимость openSUSE-SU-2019:1557-1