Описание
Security update for chromium
This update for chromium fixes the following issues:
Update to version 108.0.5359.124 (boo#1206403):
- CVE-2022-4436: Use after free in Blink Media
- CVE-2022-4437: Use after free in Mojo IPC
- CVE-2022-4438: Use after free in Blink Frames
- CVE-2022-4439: Use after free in Aura
- CVE-2022-4440: Use after free in Profiles
Список пакетов
SUSE Package Hub 15 SP3
openSUSE Leap 15.3
Ссылки
- E-Mail link for openSUSE-SU-2022:10245-1
- SUSE Security Ratings
- SUSE Bug 1205433
- SUSE CVE CVE-2022-4436 page
- SUSE CVE CVE-2022-4437 page
- SUSE CVE CVE-2022-4438 page
- SUSE CVE CVE-2022-4439 page
- SUSE CVE CVE-2022-4440 page
Описание
Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2022-4436
- SUSE Bug 1206403
Описание
Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2022-4437
- SUSE Bug 1206403
Описание
Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2022-4438
- SUSE Bug 1206403
Описание
Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2022-4439
- SUSE Bug 1206403
Описание
Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2022-4440
- SUSE Bug 1206403