Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0365-1

Опубликовано: 22 мар. 2020
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium to version 80.0.3987.149 fixes the following issues:

Chromium was update to 80.0.3987.149 (bsc#1167090):

  • CVE-2020-6422: Fixed a use after free in WebGL.
  • CVE-2020-6424: Fixed a use after free in media.
  • CVE-2020-6425: Fixed an insufficient policy enforcement in extensions.
  • CVE-2020-6426: Fixed an inappropriate implementation in V8.
  • CVE-2020-6427: Fixed a use after free in audio.
  • CVE-2020-6428: Fixed a use after free in audio.
  • CVE-2020-6429: Fixed a use after free in audio.
  • CVE-2019-20503: Fixed an out of bounds read in usersctplib.
  • CVE-2020-6449: Fixed a use after free in audio.

Список пакетов

SUSE Package Hub 12 SP3
chromedriver-80.0.3987.149-41.1
chromium-80.0.3987.149-41.1
openSUSE Leap 15.1
chromedriver-80.0.3987.149-41.1
chromium-80.0.3987.149-41.1

Описание

usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 12 SP3:chromedriver-80.0.3987.149-41.1
SUSE Package Hub 12 SP3:chromium-80.0.3987.149-41.1
openSUSE Leap 15.1:chromedriver-80.0.3987.149-41.1
openSUSE Leap 15.1:chromium-80.0.3987.149-41.1

Ссылки