Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:0893-1

Опубликовано: 28 июн. 2020
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium was updated to 83.0.4103.116 (boo#1173251):

  • CVE-2020-6509: Use after free in extensions

Chromium was updated to 83.0.4103.106 (boo#1173029):

  • CVE-2020-6505: Use after free in speech
  • CVE-2020-6506: Insufficient policy enforcement in WebView
  • CVE-2020-6507: Out of bounds write in V8

Other fixes:

  • Add patch to work with new ffmpeg wrt boo#1173292:
  • Add multimedia fix for disabled location and also try one additional patch from Debian on the same issue boo#1173107
  • Disable wayland integration on 15.x boo#1173187 boo#1173188 boo#1173254
  • Enforce to not use system borders boo#1173063

Список пакетов

openSUSE Leap 15.2
chromedriver-83.0.4103.116-lp152.2.3.1
chromium-83.0.4103.116-lp152.2.3.1

Описание

Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-83.0.4103.116-lp152.2.3.1
openSUSE Leap 15.2:chromium-83.0.4103.116-lp152.2.3.1

Ссылки

Описание

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-83.0.4103.116-lp152.2.3.1
openSUSE Leap 15.2:chromium-83.0.4103.116-lp152.2.3.1

Ссылки

Описание

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-83.0.4103.116-lp152.2.3.1
openSUSE Leap 15.2:chromium-83.0.4103.116-lp152.2.3.1

Ссылки

Описание

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-83.0.4103.116-lp152.2.3.1
openSUSE Leap 15.2:chromium-83.0.4103.116-lp152.2.3.1

Ссылки