Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2022:10123-1

Опубликовано: 16 сент. 2022
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium 105.0.5195.127 (boo#1203419):

  • CVE-2022-3195: Out of bounds write in Storage
  • CVE-2022-3196: Use after free in PDF
  • CVE-2022-3197: Use after free in PDF
  • CVE-2022-3198: Use after free in PDF
  • CVE-2022-3199: Use after free in Frames
  • CVE-2022-3200: Heap buffer overflow in Internals
  • CVE-2022-3201: Insufficient validation of untrusted input in DevTools
  • Various fixes from internal audits, fuzzing and other initiatives

Список пакетов

SUSE Package Hub 15 SP3
chromedriver-105.0.5195.127-bp154.2.29.1
chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4
chromedriver-105.0.5195.127-bp154.2.29.1
chromium-105.0.5195.127-bp154.2.29.1
openSUSE Leap 15.3
chromedriver-105.0.5195.127-bp154.2.29.1
chromium-105.0.5195.127-bp154.2.29.1
openSUSE Leap 15.4
chromedriver-105.0.5195.127-bp154.2.29.1
chromium-105.0.5195.127-bp154.2.29.1

Описание

Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки

Описание

Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP3:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP3:chromium-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromedriver-105.0.5195.127-bp154.2.29.1
SUSE Package Hub 15 SP4:chromium-105.0.5195.127-bp154.2.29.1

Ссылки
Уязвимость openSUSE-SU-2022:10123-1