Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2153-1

Опубликовано: 19 сент. 2019
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Security issues fixed:

  • CVE-2019-5870: Fixed a use-after-free in media. (boo#1150425)
  • CVE-2019-5871: Fixed a heap overflow in Skia. (boo#1150425)
  • CVE-2019-5872: Fixed a use-after-free in Mojo (boo#1150425)
  • CVE-2019-5874: Fixed a behavior that made external URIs trigger other browsers. (boo#1150425)
  • CVE-2019-5875: Fixed a URL bar spoof via download redirect. (boo#1150425)
  • CVE-2019-5876: Fixed a use-after-free in media (boo#1150425)
  • CVE-2019-5877: Fixed an out-of-bounds access in V8. (boo#1150425)
  • CVE-2019-5878: Fixed a use-after-free in V8. (boo#1150425)
  • CVE-2019-5879: Fixed an extension issue that allowed the bypass of a same origin policy. (boo#1150425)
  • CVE-2019-5880: Fixed a SameSite cookie bypass. (boo#1150425)
  • CVE-2019-5881: Fixed an arbitrary read in SwiftShader. (boo#1150425)
  • CVE-2019-13659: Fixed an URL spoof. (boo#1150425)
  • CVE-2019-13660: Fixed a full screen notification overlap. (boo#1150425)
  • CVE-2019-13661: Fixed a full screen notification spoof. (boo#1150425)
  • CVE-2019-13662: Fixed a CSP bypass. (boo#1150425)
  • CVE-2019-13663: Fixed an IDN spoof. (boo#1150425)
  • CVE-2019-13664: Fixed a CSRF bypass. (boo#1150425)
  • CVE-2019-13665: Fixed a multiple file download protection bypass. (boo#1150425)
  • CVE-2019-13666: Fixed a side channel weakness using storage size estimate. (boo#1150425)
  • CVE-2019-13667: Fixed a URI bar spoof when using external app URIs. (boo#1150425)
  • CVE-2019-13668: Fixed a global window leak via console. (boo#1150425)
  • CVE-2019-13669: Fixed an HTTP authentication spoof. (boo#1150425)
  • CVE-2019-13670: Fixed a V8 memory corruption in regex. (boo#1150425)
  • CVE-2019-13671: Fixed a dialog box that failed to show the origin. (boo#1150425)
  • CVE-2019-13673: Fixed a cross-origin information leak using devtools. (boo#1150425)
  • CVE-2019-13674: Fixed an IDN spoofing opportunity. (boo#1150425)
  • CVE-2019-13675: Fixed an error that allowed extensions to be disabled by trailing slash. (boo#1150425)
  • CVE-2019-13676: Fixed a mistakenly shown Google URI in certificate warnings. (boo#1150425)
  • CVE-2019-13677: Fixed a lack of isolation in Chrome web store origin. (boo#1150425)
  • CVE-2019-13678: Fixed a download dialog spoofing opportunity. (boo#1150425)
  • CVE-2019-13679: Fixed a the necessity of a user gesture for printing. (boo#1150425)
  • CVE-2019-13680: Fixed an IP address spoofing error. (boo#1150425)
  • CVE-2019-13681: Fixed a bypass on download restrictions. (boo#1150425)
  • CVE-2019-13682: Fixed a site isolation bypass. (boo#1150425)
  • CVE-2019-13683: Fixed an exception leaked by devtools. (boo#1150425)

Список пакетов

openSUSE Leap 15.0
chromedriver-77.0.3865.75-lp150.239.1
chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient data validation in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable extensions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Incorrect data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Inappropriate implementation in TLS in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof client IP address to websites via crafted TLS connections.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass download restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in external protocol handling in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass same origin policy via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Heap buffer overflow in Skia in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Use after free in Mojo in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient filtering in URI schemes in Google Chrome on Windows prior to 77.0.3865.75 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient data validation in downloads in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Use after free in media in Google Chrome on Android prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Out of bounds memory access in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки

Описание

Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.0:chromedriver-77.0.3865.75-lp150.239.1
openSUSE Leap 15.0:chromium-77.0.3865.75-lp150.239.1

Ссылки
Уязвимость openSUSE-SU-2019:2153-1