Описание
Security update for chromium
This update for chromium fixes the following issues:
-
Chromium updated to 84.0.4147.125 (boo#1175085)
- CVE-2020-6542: Use after free in ANGLE
- CVE-2020-6543: Use after free in task scheduling
- CVE-2020-6544: Use after free in media
- CVE-2020-6545: Use after free in audio
- CVE-2020-6546: Inappropriate implementation in installer
- CVE-2020-6547: Incorrect security UI in media
- CVE-2020-6548: Heap buffer overflow in Skia
- CVE-2020-6549: Use after free in media
- CVE-2020-6550: Use after free in IndexedDB
- CVE-2020-6551: Use after free in WebXR
- CVE-2020-6552: Use after free in Blink
- CVE-2020-6553: Use after free in offline mode
- CVE-2020-6554: Use after free in extensions
- CVE-2020-6555: Out of bounds read in WebGL
- Various fixes from internal audits, fuzzing and other initiatives
-
Disable wayland everywhere as it breaks headless and middle mouse copy everywhere: boo#1174497 boo#1175044
Список пакетов
openSUSE Leap 15.1
openSUSE Leap 15.2
Ссылки
- E-Mail link for openSUSE-SU-2020:1206-1
- SUSE Security Ratings
- SUSE Bug 1174497
- SUSE Bug 1175044
- SUSE Bug 1175085
- SUSE CVE CVE-2020-6542 page
- SUSE CVE CVE-2020-6543 page
- SUSE CVE CVE-2020-6544 page
- SUSE CVE CVE-2020-6545 page
- SUSE CVE CVE-2020-6546 page
- SUSE CVE CVE-2020-6547 page
- SUSE CVE CVE-2020-6548 page
- SUSE CVE CVE-2020-6549 page
- SUSE CVE CVE-2020-6550 page
- SUSE CVE CVE-2020-6551 page
- SUSE CVE CVE-2020-6552 page
- SUSE CVE CVE-2020-6553 page
- SUSE CVE CVE-2020-6554 page
- SUSE CVE CVE-2020-6555 page
Описание
Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6542
- SUSE Bug 1175085
Описание
Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6543
- SUSE Bug 1175085
Описание
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6544
- SUSE Bug 1175085
Описание
Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6545
- SUSE Bug 1175085
Описание
Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.
Затронутые продукты
Ссылки
- CVE-2020-6546
- SUSE Bug 1175085
Описание
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6547
- SUSE Bug 1175085
Описание
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6548
- SUSE Bug 1175085
Описание
Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6549
- SUSE Bug 1175085
Описание
Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6550
- SUSE Bug 1175085
Описание
Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6551
- SUSE Bug 1175085
Описание
Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6552
- SUSE Bug 1175085
Описание
Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6553
- SUSE Bug 1175085
Описание
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
Затронутые продукты
Ссылки
- CVE-2020-6554
- SUSE Bug 1175085
Описание
Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-6555
- SUSE Bug 1175085