Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1527-1

Опубликовано: 25 сент. 2020
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium was updated to 85.0.4183.121 (boo#1176791):

  • CVE-2020-15960: Out of bounds read in storage
  • CVE-2020-15961: Insufficient policy enforcement in extensions
  • CVE-2020-15962: Insufficient policy enforcement in serial
  • CVE-2020-15963: Insufficient policy enforcement in extensions
  • CVE-2020-15965: Out of bounds write in V8
  • CVE-2020-15966: Insufficient policy enforcement in extensions
  • CVE-2020-15964: Insufficient data validation in media

Список пакетов

openSUSE Leap 15.1
chromedriver-85.0.4183.121-lp152.2.33.1
chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2
chromedriver-85.0.4183.121-lp152.2.33.1
chromium-85.0.4183.121-lp152.2.33.1

Описание

Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки

Описание

Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.1:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.1:chromium-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromedriver-85.0.4183.121-lp152.2.33.1
openSUSE Leap 15.2:chromium-85.0.4183.121-lp152.2.33.1

Ссылки