Описание
Security update for chromium
This update for chromium to version 80.0.3987.149 fixes the following issues:
Chromium was update to 80.0.3987.149 (bsc#1167090):
- CVE-2020-6422: Fixed a use after free in WebGL.
- CVE-2020-6424: Fixed a use after free in media.
- CVE-2020-6425: Fixed an insufficient policy enforcement in extensions.
- CVE-2020-6426: Fixed an inappropriate implementation in V8.
- CVE-2020-6427: Fixed a use after free in audio.
- CVE-2020-6428: Fixed a use after free in audio.
- CVE-2020-6429: Fixed a use after free in audio.
- CVE-2019-20503: Fixed an out of bounds read in usersctplib.
- CVE-2020-6449: Fixed a use after free in audio.
Список пакетов
SUSE Package Hub 12 SP3
openSUSE Leap 15.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0365-1
- SUSE Security Ratings
- SUSE Bug 1167090
- SUSE CVE CVE-2019-20503 page
- SUSE CVE CVE-2020-6422 page
- SUSE CVE CVE-2020-6424 page
- SUSE CVE CVE-2020-6425 page
- SUSE CVE CVE-2020-6426 page
- SUSE CVE CVE-2020-6427 page
- SUSE CVE CVE-2020-6428 page
- SUSE CVE CVE-2020-6429 page
- SUSE CVE CVE-2020-6449 page
Описание
usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
Затронутые продукты
Ссылки
- CVE-2019-20503
- SUSE Bug 1166238
- SUSE Bug 1167090
Описание
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6422
- SUSE Bug 1167090
Описание
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6424
- SUSE Bug 1167090
Описание
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
Затронутые продукты
Ссылки
- CVE-2020-6425
- SUSE Bug 1167090
Описание
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6426
- SUSE Bug 1167090
Описание
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6427
- SUSE Bug 1167090
Описание
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6428
- SUSE Bug 1167090
Описание
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6429
- SUSE Bug 1167090
Описание
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6449
- SUSE Bug 1167090