Описание
Security update for chromium
This update for chromium fixes the following issues:
Chromium 110.0.5481.77 (boo#1208029):
- CVE-2023-0696: Type Confusion in V8
 - CVE-2023-0697: Inappropriate implementation in Full screen mode
 - CVE-2023-0698: Out of bounds read in WebRTC
 - CVE-2023-0699: Use after free in GPU
 - CVE-2023-0700: Inappropriate implementation in Download
 - CVE-2023-0701: Heap buffer overflow in WebUI
 - CVE-2023-0702: Type Confusion in Data Transfer
 - CVE-2023-0703: Type Confusion in DevTools
 - CVE-2023-0704: Insufficient policy enforcement in DevTools
 - CVE-2023-0705: Integer overflow in Core
 - Various fixes from internal audits, fuzzing and other initiatives
 
- build with bundled libavif
 
Список пакетов
SUSE Package Hub 15 SP4
openSUSE Leap 15.4
Ссылки
- E-Mail link for openSUSE-SU-2023:0045-1
 - SUSE Security Ratings
 - SUSE Bug 1208029
 - SUSE CVE CVE-2023-0696 page
 - SUSE CVE CVE-2023-0697 page
 - SUSE CVE CVE-2023-0698 page
 - SUSE CVE CVE-2023-0699 page
 - SUSE CVE CVE-2023-0700 page
 - SUSE CVE CVE-2023-0701 page
 - SUSE CVE CVE-2023-0702 page
 - SUSE CVE CVE-2023-0703 page
 - SUSE CVE CVE-2023-0704 page
 - SUSE CVE CVE-2023-0705 page
 
Описание
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0696
 - SUSE Bug 1208029
 
Описание
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0697
 - SUSE Bug 1208029
 
Описание
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0698
 - SUSE Bug 1208029
 
Описание
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0699
 - SUSE Bug 1208029
 
Описание
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0700
 - SUSE Bug 1208029
 
Описание
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0701
 - SUSE Bug 1208029
 
Описание
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0702
 - SUSE Bug 1208029
 
Описание
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0703
 - SUSE Bug 1208029
 
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0704
 - SUSE Bug 1208029
 
Описание
Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0705
 - SUSE Bug 1208029