Описание
Security update for chromium
This update for chromium fixes the following issues:
Chromium 110.0.5481.77 (boo#1208029):
- CVE-2023-0696: Type Confusion in V8
- CVE-2023-0697: Inappropriate implementation in Full screen mode
- CVE-2023-0698: Out of bounds read in WebRTC
- CVE-2023-0699: Use after free in GPU
- CVE-2023-0700: Inappropriate implementation in Download
- CVE-2023-0701: Heap buffer overflow in WebUI
- CVE-2023-0702: Type Confusion in Data Transfer
- CVE-2023-0703: Type Confusion in DevTools
- CVE-2023-0704: Insufficient policy enforcement in DevTools
- CVE-2023-0705: Integer overflow in Core
- Various fixes from internal audits, fuzzing and other initiatives
- build with bundled libavif
Список пакетов
SUSE Package Hub 15 SP4
openSUSE Leap 15.4
Ссылки
- E-Mail link for openSUSE-SU-2023:0045-1
- SUSE Security Ratings
- SUSE Bug 1208029
- SUSE CVE CVE-2023-0696 page
- SUSE CVE CVE-2023-0697 page
- SUSE CVE CVE-2023-0698 page
- SUSE CVE CVE-2023-0699 page
- SUSE CVE CVE-2023-0700 page
- SUSE CVE CVE-2023-0701 page
- SUSE CVE CVE-2023-0702 page
- SUSE CVE CVE-2023-0703 page
- SUSE CVE CVE-2023-0704 page
- SUSE CVE CVE-2023-0705 page
Описание
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0696
- SUSE Bug 1208029
Описание
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0697
- SUSE Bug 1208029
Описание
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0698
- SUSE Bug 1208029
Описание
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0699
- SUSE Bug 1208029
Описание
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0700
- SUSE Bug 1208029
Описание
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0701
- SUSE Bug 1208029
Описание
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0702
- SUSE Bug 1208029
Описание
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0703
- SUSE Bug 1208029
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0704
- SUSE Bug 1208029
Описание
Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0705
- SUSE Bug 1208029