Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2023:0045-1

Опубликовано: 13 фев. 2023
Источник: suse-cvrf

Описание

Security update for chromium

This update for chromium fixes the following issues:

Chromium 110.0.5481.77 (boo#1208029):

  • CVE-2023-0696: Type Confusion in V8
  • CVE-2023-0697: Inappropriate implementation in Full screen mode
  • CVE-2023-0698: Out of bounds read in WebRTC
  • CVE-2023-0699: Use after free in GPU
  • CVE-2023-0700: Inappropriate implementation in Download
  • CVE-2023-0701: Heap buffer overflow in WebUI
  • CVE-2023-0702: Type Confusion in Data Transfer
  • CVE-2023-0703: Type Confusion in DevTools
  • CVE-2023-0704: Insufficient policy enforcement in DevTools
  • CVE-2023-0705: Integer overflow in Core
  • Various fixes from internal audits, fuzzing and other initiatives
  • build with bundled libavif

Список пакетов

SUSE Package Hub 15 SP4
chromedriver-110.0.5481.77-bp154.2.67.1
chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4
chromedriver-110.0.5481.77-bp154.2.67.1
chromium-110.0.5481.77-bp154.2.67.1

Описание

Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки

Описание

Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)


Затронутые продукты
SUSE Package Hub 15 SP4:chromedriver-110.0.5481.77-bp154.2.67.1
SUSE Package Hub 15 SP4:chromium-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromedriver-110.0.5481.77-bp154.2.67.1
openSUSE Leap 15.4:chromium-110.0.5481.77-bp154.2.67.1

Ссылки
Уязвимость openSUSE-SU-2023:0045-1