Описание
Security update for opera
This update for opera fixes the following issues:
Update to 96.0.4693.20
- CHR-9191 Update Chromium on desktop-stable-110-4693 to 110.0.5481.78
- CHR-9197 Update Chromium on desktop-stable-110-4693 to 110.0.5481.100
- DNA-105308 Translations for O96
- DNA-105395 Fix missing resources errors on About and Update & Recovery pages
-
Complete Opera 96.0 changelog at: https://blogs.opera.com/desktop/changelog-for-96/
-
The update to chromium 110.0.5481.78 fixes following issues: CVE-2023-0696, CVE-2023-0697, CVE-2023-0698, CVE-2023-0699, CVE-2023-0700, CVE-2023-0701, CVE-2023-0702, CVE-2023-0703, CVE-2023-0704, CVE-2023-0705
Update to 95.0.4635.46
- DNA-104601 Crash at opera::EasyShareButtonControllerTabHelper::StartOnboarding()
- DNA-104936 Set new Baidu search string
- DNA-105084 Prepare to turning on 'Rich entities'
Update to 95.0.4635.37
- DNA-104366 Turn #speed-dial-custom-image on developer
- DNA-104370 Pictures in news don’t show
- DNA-104384 [News] Change News to be disabled by default
- DNA-104393 [Continue on] Weird look of item counter in collapsed Continue shopping after refreshing page
- DNA-104394 [Continue on] Continue shopping show up collapsed
- DNA-104421 Mechanism to detect installed player
- DNA-104439 Merge with GX implementation
- DNA-104492 [Stable A/B Test] React Start Page for Austria 50%
- DNA-104523 [Add to Opera][Folders][Edit] Black font on dark background in modals when light theme with dark wallpaper is selected
- DNA-104525 [Choose language and country] Modal does not adapt when wallpaper does not match theme
- DNA-104609 [SD][Folders] Incorrect order of tiles in folder when merging folder with single tile
- DNA-104612 [News] Invisible button in news category.
- DNA-104614 Do not allow to create folder with the same name to prevent automerging
- DNA-104898 [Edit tile] Adjust icon size of tile in edit-form-modal
Список пакетов
openSUSE Leap 15.4 NonFree
Ссылки
- E-Mail link for openSUSE-SU-2023:0063-1
- SUSE Security Ratings
- SUSE CVE CVE-2023-0696 page
- SUSE CVE CVE-2023-0697 page
- SUSE CVE CVE-2023-0698 page
- SUSE CVE CVE-2023-0699 page
- SUSE CVE CVE-2023-0700 page
- SUSE CVE CVE-2023-0701 page
- SUSE CVE CVE-2023-0702 page
- SUSE CVE CVE-2023-0703 page
- SUSE CVE CVE-2023-0704 page
- SUSE CVE CVE-2023-0705 page
Описание
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0696
- SUSE Bug 1208029
Описание
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0697
- SUSE Bug 1208029
Описание
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-0698
- SUSE Bug 1208029
Описание
Use after free in GPU in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page and browser shutdown. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0699
- SUSE Bug 1208029
Описание
Inappropriate implementation in Download in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0700
- SUSE Bug 1208029
Описание
Heap buffer overflow in WebUI in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interaction . (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0701
- SUSE Bug 1208029
Описание
Type confusion in Data Transfer in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0702
- SUSE Bug 1208029
Описание
Type confusion in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-0703
- SUSE Bug 1208029
Описание
Insufficient policy enforcement in DevTools in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to bypass same origin policy and proxy settings via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0704
- SUSE Bug 1208029
Описание
Integer overflow in Core in Google Chrome prior to 110.0.5481.77 allowed a remote attacker who had one a race condition to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Затронутые продукты
Ссылки
- CVE-2023-0705
- SUSE Bug 1208029