Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1154-1

Опубликовано: 06 авг. 2020
Источник: suse-cvrf

Описание

Security update of chromium

Chromium was updated to 84.0.4147.105 (boo#1174582):

  • CVE-2020-6537: Type Confusion in V8
  • CVE-2020-6538: Inappropriate implementation in WebView
  • CVE-2020-6532: Use after free in SCTP
  • CVE-2020-6539: Use after free in CSS
  • CVE-2020-6540: Heap buffer overflow in Skia
  • CVE-2020-6541: Use after free in WebUSB

Список пакетов

openSUSE Leap 15.1
chromedriver-84.0.4147.105-lp152.2.9.1
chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2
chromedriver-84.0.4147.105-lp152.2.9.1
chromium-84.0.4147.105-lp152.2.9.1

Описание

Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки

Описание

Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки

Описание

Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки

Описание

Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки

Описание

Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.1:chromium-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromedriver-84.0.4147.105-lp152.2.9.1
openSUSE Leap 15.2:chromium-84.0.4147.105-lp152.2.9.1

Ссылки