Описание
Security update for chromium
This update for chromium fixes the following issues:
Update to 87.0.4280.88 (boo#1179576)
- CVE-2020-16037: Use after free in clipboard
- CVE-2020-16038: Use after free in media
- CVE-2020-16039: Use after free in extensions
- CVE-2020-16040: Insufficient data validation in V8
- CVE-2020-16041: Out of bounds read in networking
- CVE-2020-16042: Uninitialized Use in V8
Список пакетов
openSUSE Leap 15.2
Ссылки
- E-Mail link for openSUSE-SU-2020:2181-1
- SUSE Security Ratings
- SUSE Bug 1179576
- SUSE CVE CVE-2020-16037 page
- SUSE CVE CVE-2020-16038 page
- SUSE CVE CVE-2020-16039 page
- SUSE CVE CVE-2020-16040 page
- SUSE CVE CVE-2020-16041 page
- SUSE CVE CVE-2020-16042 page
Описание
Use after free in clipboard in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16037
- SUSE Bug 1179576
Описание
Use after free in media in Google Chrome on OS X prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16038
- SUSE Bug 1179576
Описание
Use after free in extensions in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16039
- SUSE Bug 1179576
Описание
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16040
- SUSE Bug 1179576
Описание
Out of bounds read in networking in Google Chrome prior to 87.0.4280.88 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16041
- SUSE Bug 1179576
Описание
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Затронутые продукты
Ссылки
- CVE-2020-16042
- SUSE Bug 1179576
- SUSE Bug 1180039