Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0513-1

Опубликовано: 05 апр. 2021
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Update to 89.0.4389.114 boo#1184256

  • CVE-2021-21194: Use after free in screen capture
  • CVE-2021-21195: Use after free in V8
  • CVE-2021-21196: Heap buffer overflow in TabStrip
  • CVE-2021-21197: Heap buffer overflow in TabStrip
  • CVE-2021-21198: Out of bounds read in IPC
  • CVE-2021-21199: Use Use after free in Aura

Список пакетов

openSUSE Leap 15.2
chromedriver-89.0.4389.114-lp152.2.83.1
chromium-89.0.4389.114-lp152.2.83.1

Описание

Use after free in screen sharing in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки

Описание

Heap buffer overflow in TabStrip in Google Chrome on Windows prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки

Описание

Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки

Описание

Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки

Описание

Use after free in Aura in Google Chrome on Linux prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
openSUSE Leap 15.2:chromedriver-89.0.4389.114-lp152.2.83.1
openSUSE Leap 15.2:chromium-89.0.4389.114-lp152.2.83.1

Ссылки