Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2020:1952-1

Опубликовано: 17 нояб. 2020
Источник: suse-cvrf

Описание

Security update for opera

This update for opera fixes the following issues:

Opera was updated to version 72.0.3815.320

  • CHR-8177 Update chromium on desktop-stable-86-3815 to 86.0.4240.183

  • DNA-89748 ‘Manage Extensions’ dialog is displayed with preloaded extensions

  • DNA-89766 Address bar does not respond to actions

  • The update to chromium 86.0.4240.183 fixes following issues: CVE-2020-16004, CVE-2020-16005, CVE-2020-16006, CVE-2020-16007, CVE-2020-16008, CVE-2020-16009, CVE-2020-16011

  • Update to version 72.0.3815.200

    • DNA-87150 Speed Dial tile can’t be dragged to proper place
    • DNA-89632 Improve hovering over icons
    • DNA-89647 [Light mode] Wrong URL color in ‘Add Site’ section
    • DNA-89791 Typo in Spanish
  • The update to chromium 86.0.4240.111 fixes following issues: CVE-2020-16000, CVE-2020-16001, CVE-2020-16002, CVE-2020-15999, CVE-2020-16003

  • Complete Opera 72.0 changelog at: https://blogs.opera.com/desktop/changelog-for-72/

  • Update to version 71.0.3770.271

    • DNA-88353 Crash at opera::TabCyclerView::HighlightContents (content::WebContents*, bool)
    • DNA-89177 Device update request should only be called when FCM token has changed
    • DNA-89186 Handle device expired case in all server calls
    • DNA-89202 Pages are rendered in dark mode when force dark mode prefs were synced from Opera GX
    • DNA-89247 [Mac] Fullscreen video broken if sidebar is hidden
    • DNA-89298 Some elements of VPN popup are misaligned to design
    • DNA-89305 Crash after closing Downloads pop-up

Список пакетов

openSUSE Leap 15.1 NonFree
opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree
opera-72.0.3815.320-lp152.2.21.1

Описание

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate privilege via a crafted filesystem.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack corruption via a crafted WebRTC packet.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки

Описание

Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.1 NonFree:opera-72.0.3815.320-lp152.2.21.1
openSUSE Leap 15.2 NonFree:opera-72.0.3815.320-lp152.2.21.1

Ссылки