Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0040-1

Опубликовано: 10 янв. 2021
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

  • Update to 87.0.4280.141 (boo#1180645)

    • CVE-2021-21106: Use after free in autofill
    • CVE-2021-21107: Use after free in drag and drop
    • CVE-2021-21108: Use after free in media
    • CVE-2021-21109: Use after free in payments
    • CVE-2021-21110: Use after free in safe browsing
    • CVE-2021-21111: Insufficient policy enforcement in WebUI
    • CVE-2021-21112: Use after free in Blink
    • CVE-2021-21113: Heap buffer overflow in Skia
    • CVE-2020-16043: Insufficient data validation in networking
    • CVE-2021-21114: Use after free in audio
    • CVE-2020-15995: Out of bounds write in V8
    • CVE-2021-21115: Use after free in safe browsing
    • CVE-2021-21116: Heap buffer overflow in audio
  • Use main URLs instead of redirects in master preferences

Список пакетов

openSUSE Leap 15.2
chromedriver-87.0.4280.141-lp152.2.60.1
chromium-87.0.4280.141-lp152.2.60.1

Описание

Out of bounds write in V8 in Google Chrome prior to 86.0.4240.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки

Описание

Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-87.0.4280.141-lp152.2.60.1
openSUSE Leap 15.2:chromium-87.0.4280.141-lp152.2.60.1

Ссылки
Уязвимость openSUSE-SU-2021:0040-1