Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1324-1

Опубликовано: 02 сент. 2020
Источник: suse-cvrf

Описание

Security update for opera

This update for opera fixes the following issues:

Update to version 70.0.3728.133

  • CHR-8053 Update chromium on desktop-stable-84-3728 to 84.0.4147.125

  • DNA-87289 Crash at views::NativeWidgetMacNSWindowHost:: OnNativeViewHostDetach(views::View const*)

  • DNA-87831 [Linux] Sidebar panel cannot be pinned

  • DNA-88057 [Win] Black rectangle flickers at the bottom of the page on startup

  • DNA-88157 Sidebar Messenger too low in FullScreen mode

  • DNA-88238 [macOS 10.15] Toolbar buttons not visible on inactive tab

  • The update to chromium 84.0.4147.125 fixes following issues:

    • CVE-2020-6542, CVE-2020-6543, CVE-2020-6544, CVE-2020-6545, CVE-2020-6546, CVE-2020-6547, CVE-2020-6548, CVE-2020-6549, CVE-2020-6550, CVE-2020-6551, CVE-2020-6552, CVE-2020-6553, CVE-2020-6554, CVE-2020-6555
  • Update to version 70.0.3728.119

    • DNA-88215 Introduce easy-setup-hint-ref feature flag
  • Update to version 70.0.3728.106

    • DNA-88014 [Mac] Toolbar in fullscreen disabled after using fullscreen from videoplayer
  • Update to version 70.0.3728.95

    • CHR-8026 Update chromium on desktop-stable-84-3728 to 84.0.4147.105
    • DNA-86340 Wrong link to the help page
    • DNA-87394 [Big Sur] Some popovers have incorrectly themed arrow
    • DNA-87647 [Win] The [+] button flickers after creating a new tab
    • DNA-87794 Crash at aura::Window::SetVisible(bool)
    • DNA-87796 Search in tabs should closed on second click
    • DNA-87863 Parameter placing issue in all languages
  • The update to chromium 84.0.4147.105 fixes following issues:

    • CVE-2020-6537, CVE-2020-6538, CVE-2020-6532, CVE-2020-6539, CVE-2020-6540, CVE-2020-6541

Список пакетов

openSUSE Leap 15.2 NonFree
opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in task scheduling in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Inappropriate implementation in installer in Google Chrome prior to 84.0.4147.125 allowed a local attacker to potentially elevate privilege via a crafted filesystem.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.125 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in IndexedDB in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in WebXR in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки

Описание

Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2 NonFree:opera-70.0.3728.133-lp152.2.15.1

Ссылки
Уязвимость openSUSE-SU-2020:1324-1