Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1600-1

Опубликовано: 20 дек. 2021
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium 96.0.4664.110 (boo#1193713):

  • CVE-2021-4098: Insufficient data validation in Mojo
  • CVE-2021-4099: Use after free in Swiftshader
  • CVE-2021-4100: Object lifecycle issue in ANGLE
  • CVE-2021-4101: Heap buffer overflow in Swiftshader
  • CVE-2021-4102: Use after free in V8

Список пакетов

SUSE Package Hub 15 SP3
chromedriver-96.0.4664.110-bp153.2.48.1
chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3
chromedriver-96.0.4664.110-bp153.2.48.1
chromium-96.0.4664.110-bp153.2.48.1

Описание

Insufficient data validation in Mojo in Google Chrome prior to 96.0.4664.110 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-96.0.4664.110-bp153.2.48.1
SUSE Package Hub 15 SP3:chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromedriver-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromium-96.0.4664.110-bp153.2.48.1

Ссылки

Описание

Use after free in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-96.0.4664.110-bp153.2.48.1
SUSE Package Hub 15 SP3:chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromedriver-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromium-96.0.4664.110-bp153.2.48.1

Ссылки

Описание

Object lifecycle issue in ANGLE in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-96.0.4664.110-bp153.2.48.1
SUSE Package Hub 15 SP3:chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromedriver-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromium-96.0.4664.110-bp153.2.48.1

Ссылки

Описание

Heap buffer overflow in Swiftshader in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-96.0.4664.110-bp153.2.48.1
SUSE Package Hub 15 SP3:chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromedriver-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromium-96.0.4664.110-bp153.2.48.1

Ссылки

Описание

Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-96.0.4664.110-bp153.2.48.1
SUSE Package Hub 15 SP3:chromium-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromedriver-96.0.4664.110-bp153.2.48.1
openSUSE Leap 15.3:chromium-96.0.4664.110-bp153.2.48.1

Ссылки