Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1206-1

Опубликовано: 14 авг. 2020
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

  • Chromium updated to 84.0.4147.125 (boo#1175085)

    • CVE-2020-6542: Use after free in ANGLE
    • CVE-2020-6543: Use after free in task scheduling
    • CVE-2020-6544: Use after free in media
    • CVE-2020-6545: Use after free in audio
    • CVE-2020-6546: Inappropriate implementation in installer
    • CVE-2020-6547: Incorrect security UI in media
    • CVE-2020-6548: Heap buffer overflow in Skia
    • CVE-2020-6549: Use after free in media
    • CVE-2020-6550: Use after free in IndexedDB
    • CVE-2020-6551: Use after free in WebXR
    • CVE-2020-6552: Use after free in Blink
    • CVE-2020-6553: Use after free in offline mode
    • CVE-2020-6554: Use after free in extensions
    • CVE-2020-6555: Out of bounds read in WebGL
    • Various fixes from internal audits, fuzzing and other initiatives
  • Disable wayland everywhere as it breaks headless and middle mouse copy everywhere: boo#1174497 boo#1175044

Список пакетов

openSUSE Leap 15.1
chromedriver-84.0.4147.125-lp152.2.12.2
chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2
chromedriver-84.0.4147.125-lp152.2.12.2
chromium-84.0.4147.125-lp152.2.12.2

Описание

Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки

Описание

Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.1:chromium-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromedriver-84.0.4147.125-lp152.2.12.2
openSUSE Leap 15.2:chromium-84.0.4147.125-lp152.2.12.2

Ссылки
Уязвимость openSUSE-SU-2020:1206-1