Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0604-1

Опубликовано: 02 мая 2020
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium was updated to 81.0.4044.129 (boo#1170107):

  • CVE-2020-0561: Fixed a use after free in storage
  • CVE-2020-6462: Fixed a use after free in task scheduling
  • CVE-2020-6459: Fixed a use after free in payments
  • CVE-2020-6460: Fixed an insufficient data validation in URL formatting
  • CVE-2020-6458: Fixed an out of bounds read and write in PDFium

Список пакетов

SUSE Package Hub 15 SP1
chromedriver-81.0.4044.129-bp151.3.75.1
chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1
chromedriver-81.0.4044.129-bp151.3.75.1
chromium-81.0.4044.129-bp151.3.75.1

Описание

Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.


Затронутые продукты
SUSE Package Hub 15 SP1:chromedriver-81.0.4044.129-bp151.3.75.1
SUSE Package Hub 15 SP1:chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromedriver-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromium-81.0.4044.129-bp151.3.75.1

Ссылки

Описание

Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.


Затронутые продукты
SUSE Package Hub 15 SP1:chromedriver-81.0.4044.129-bp151.3.75.1
SUSE Package Hub 15 SP1:chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromedriver-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromium-81.0.4044.129-bp151.3.75.1

Ссылки

Описание

Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP1:chromedriver-81.0.4044.129-bp151.3.75.1
SUSE Package Hub 15 SP1:chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromedriver-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromium-81.0.4044.129-bp151.3.75.1

Ссылки

Описание

Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name.


Затронутые продукты
SUSE Package Hub 15 SP1:chromedriver-81.0.4044.129-bp151.3.75.1
SUSE Package Hub 15 SP1:chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromedriver-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromium-81.0.4044.129-bp151.3.75.1

Ссылки

Описание

Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP1:chromedriver-81.0.4044.129-bp151.3.75.1
SUSE Package Hub 15 SP1:chromium-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromedriver-81.0.4044.129-bp151.3.75.1
openSUSE Leap 15.1:chromium-81.0.4044.129-bp151.3.75.1

Ссылки
Уязвимость openSUSE-SU-2020:0604-1