Описание
Security update for chromium
This update for chromium fixes the following issues:
Chromium 112.0.5615.165 (boo#1210618):
- CVE-2023-2133: Out of bounds memory access in Service Worker API
- CVE-2023-2134: Out of bounds memory access in Service Worker API
- CVE-2023-2135: Use after free in DevTools
- CVE-2023-2136: Integer overflow in Skia
- CVE-2023-2137: Heap buffer overflow in sqlite
Список пакетов
SUSE Package Hub 15 SP4
openSUSE Leap 15.4
Ссылки
- E-Mail link for openSUSE-SU-2023:0093-1
- SUSE Security Ratings
- SUSE Bug 1210618
- SUSE CVE CVE-2023-2133 page
- SUSE CVE CVE-2023-2134 page
- SUSE CVE CVE-2023-2135 page
- SUSE CVE CVE-2023-2136 page
- SUSE CVE CVE-2023-2137 page
Описание
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-2133
- SUSE Bug 1210618
Описание
Out of bounds memory access in Service Worker API in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-2134
- SUSE Bug 1210618
Описание
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-2135
- SUSE Bug 1210618
Описание
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Затронутые продукты
Ссылки
- CVE-2023-2136
- SUSE Bug 1210618
Описание
Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Затронутые продукты
Ссылки
- CVE-2023-2137
- SUSE Bug 1210618
- SUSE Bug 1210660